SillyTavern has a reflected XSS vulnerability in the CORS proxy middleware
- Severity:
- Medium
Description
Fixed in SillyTavern 1.18.0: a user-provided URL is no longer reflected in the HTTP response body.
Recommendation
Update the sillytavern package to the latest compatible version. Followings are version details:
- Affected version(s): <= 1.17.0
- Patched version(s): 1.18.0
References
Related Issues
- SillyTavern has a SSRF vulnerability in the CORS proxy middleware - CVE-2026-44652
- NotChatbot WebChat has a stored cross-site scripting (XSS) vulnerability - CVE-2026-30048
- Code Snippet GeSHi plugin in CKEditor 4 has reflected cross-site scripting (XSS) vulnerability - CVE-2024-43407
- Trix has a Stored XSS vulnerability through serialized attributes - CVE-2026-73426
You might also like:
- Tags:
- npm
- sillytavern
Anything's wrong? Let us know Last updated on June 09, 2026


