CVE-2026-34526 identifies a Server-Side Request Forgery (SSRF) vulnerability in SillyTavern versions prior to 1.17.0. This flaw arises from incomplete IP validation in the `src/endpoints/search.js` component, which fails to properly restrict requests to 'localhost', IPv6 loopback addresses, or DNS names resolving to internal IPs. Rated Medium with a CVSS score of 5.0, the vulnerability requires low privileges and no user interaction, but its impact is mitigated as exploitation is limited to services on default ports (80/443). There is no evidence of active exploitation, and no public exploit code is available, with minimal community discussion or media coverage. Organizations using affected versions should upgrade to 1.17.0 or later.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.17.0CPE matchmatch criteria | cpe:2.3:a:sillytavern:sillytavern:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.