Vulnerabilities/

SillyTavern has a SSRF vulnerability in the CORS proxy middleware

Severity:
Medium

Description

SillyTavern 1.18.0 added a generic server-side request filter (Private Request Whitelisting).

Recommendation

Update the sillytavern package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
sillytavern
Anything's wrong? Let us know Last updated on May 12, 2026