Description
The web UI for SillyTavern is susceptible to DNS rebinding, allowing attackers to perform actions like install malicious extensions, read chats, inject arbitrary HTML for phishing, etc.
Recommendation
Update the sillytavern package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.13.4
- Patched version(s): 1.13.4
References
Could your website be exposed too?
SmartScanner can check your website for SillyTavern Web Interface Vulnerable DNS Rebinding and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Microsoft Playwright MCP Server vulnerable to DNS Rebinding Attack; Allows Attackers Access to All Server Tools - CVE-2025-9611
- DiracX-Web is vulnerable to attack through an Open Redirect on its login page - CVE-2025-54066
- Lobe Chat vulnerable to Server-Side Request Forgery with native web fetch module - CVE-2025-62505
- MCPHub's ServerController is vulnerable to Command Injection - CVE-2025-11285


