Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-59159

32
FAUCET Score

CVE-2025-59159 is a critical DNS rebinding vulnerability affecting SillyTavern, a local user interface for AI models, in versions prior to 1.13.4. This flaw allows attackers to execute malicious actions like installing extensions, reading chats, and injecting HTML for phishing. With a CVSS score of 9.6 (CRITICAL), the vulnerability has a network attack vector, low complexity, and high impact on confidentiality, integrity, and availability. While a patch exists in version 1.13.4, requiring users to enable a host whitelist, there is currently no evidence of active exploitation, public exploit code, or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
SillyTavernSillyTavern
< 1.13.4CNA affected

CVSS Data

CVSS version used by this source: 3.1

9.6CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
14.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 11th percentile among its peer group of 834 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

npmpatch availablevia ghsa
Product: sillytavernFixed in: 1.13.4

Vendor Advisories (1)

npmGHSA-7cxj-w27x-x78qcritical

SillyTavern Web Interface Vulnerable DNS Rebinding

Oct 6, 2025

References

docs.sillytavern.app / administration/config-yaml
docs.sillytavern.app / administration
github.com / SillyTavern/SillyTavern/commit/d134abd50e4a416e3b81233242583b0a23f38320
github.com / SillyTavern/SillyTavern/releases/tag/1.13.4
github.com / SillyTavern/SillyTavern/security/advisories/GHSA-7cxj-w27x-x78q