Sillytavern is a chat-interface application with a niche vulnerability footprint concentrated in its core product, where the durable signal centers on input-path handling and server interaction issues such as path traversal, server-side request forgery, and external control of file names or paths. These weakness classes reflect the application's file-access and network-request architecture; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sillytavern over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-34524HIGH SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice model | Apr 2, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-34522HIGH SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice model | Apr 2, 2026 | 8.1 | 27 | NO | NO |
CVE-2026-26286HIGH SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice model | Feb 19, 2026 | 8.5 | 27 | NO | NO |
CVE-2026-34526MEDIUM SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice model | Apr 2, 2026 | 5.0 | 19 | NO | NO |
CVE-2026-34523MEDIUM SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice model | Apr 2, 2026 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sillytavern.
Media articles that mention a CVE ID that affects a product developed by Sillytavern — matched by CVE ID, not by vendor name.