Description
The web UI for SillyTavern is susceptible to DNS rebinding, allowing attackers to perform actions like install malicious extensions, read chats, inject arbitrary HTML for phishing, etc.
Recommendation
Update the sillytavern package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.13.4
- Patched version(s): 1.13.4
References
- GHSA-7cxj-w27x-x78q
- docs.sillytavern.app
- CVE-2025-59159
- CWE-346
- CWE-940
- CAPEC-310
- OWASP 2021-A6
- OWASP 2021-A7
Related Issues
- Microsoft Playwright MCP Server vulnerable to DNS Rebinding Attack; Allows Attackers Access to All Server Tools - CVE-2025-9611
- DiracX-Web is vulnerable to attack through an Open Redirect on its login page - CVE-2025-54066
- Lobe Chat vulnerable to Server-Side Request Forgery with native web fetch module - CVE-2025-62505
- MCPHub's ServerController is vulnerable to Command Injection - CVE-2025-11285
You might also like:
- Tags:
- npm
- sillytavern
Anything's wrong? Let us know Last updated on October 06, 2025


