Description
SillyTavern 1.18.0 added a generic server-side request filter (Private Request Whitelisting).
Recommendation
Update the sillytavern package to the latest compatible version. Followings are version details:
- Affected version(s): <= 1.17.0
- Patched version(s): 1.18.0
References
Could your website be exposed too?
SmartScanner can check your website for SillyTavern has a SSRF vulnerability in the CORS proxy middleware and gives you actionable findings to investigate.
Start a free scanRelated Issues
- SillyTavern has a reflected XSS vulnerability in the CORS proxy middleware - CVE-2026-44651
- SillyTavern: SSRF in SearXNG Search Proxy via Unvalidated baseUrl - CVE-2026-46372
- Axios: no_proxy bypass via IP alias allows SSRF - CVE-2026-42038
- Velocity.js has a Prototype Pollution vulnerability through #set path assignment - CVE-2026-44966
You might also like:
See something that needs correcting? Let us knowUpdated June 09, 2026


