CVE-2025-59159 is a critical DNS rebinding vulnerability affecting SillyTavern, a local user interface for AI models, in versions prior to 1.13.4. This flaw allows attackers to execute malicious actions like installing extensions, reading chats, and injecting HTML for phishing. With a CVSS score of 9.6 (CRITICAL), the vulnerability has a network attack vector, low complexity, and high impact on confidentiality, integrity, and availability. While a patch exists in version 1.13.4, requiring users to enable a host whitelist, there is currently no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| SillyTavern | SillyTavern | < 1.13.4CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.