PricingCase studies Login Start trial
Plugin Icon

sillytavern

N/A

Developer

N/A

Latest version

N/A

Installations

N/A

Last updated

Npm Npm
No VDP
Claim ownership
Report vulnerability
    VulnerabilitiesSecurity Contributors

Vulnerability history

0 present
11 patched
0 Mitigation rules
  • NPM: SillyTavern: SSRF in SearXNG Search Proxy via Unvalidated baseUrl
    <= 1.17.0
    13 hours ago
  • NPM: SillyTavern has a SSRF vulnerability in the CORS proxy middleware
    <= 1.17.0
    7 days ago
  • NPM: SillyTavern has a reflected XSS vulnerability in the CORS proxy middleware
    <= 1.17.0
    7 days ago
  • NPM: SillyTavern has a Path Traversal issue
    <= 1.17.0
    7 days ago
  • NPM: SillyTavern has Authentication Bypass via SSO Header Injection
    <= 1.17.0
    7 days ago
  • NPM: SillyTavern: Existing sessions are not invalidated after password change, allowing session reuse and account takeover
    <= 1.17.0
    7 days ago
  • NPM: SillyTavern: Incomplete IP validation in /api/search/visit allows SSRF via localhost and IPv6
    <= 1.16.0
    01/04/2026
  • NPM: SillyTavern: Path Traversal in `/api/chats/export` and `/api/chats/delete` allows arbitrary file read/delete within user data root
    <= 1.16.0
    01/04/2026
  • NPM: SillyTavern: Path Traversal allows file existence oracle
    <= 1.16.0
    01/04/2026
  • NPM: SillyTavern has a path traversal in `/api/chats/import` allows arbitrary file write outside intended chat directory
    <= 1.16.0
    01/04/2026
  • NPM: SillyTavern Web Interface Vulnerable DNS Rebinding
    < 1.13.4
    06/10/2025

Vulnerability mitigation

  • Pricing
  • Application security (SCA)
  • RapidMitigate New
  • Threat Intelligence (API)
  • VS Monarx
  • VS Imunify360
  • VS Wordfence
  • Documentation
  • Service status
  • Log in

Code security

  • Managed VDP New
  • Active VDP directory 1,194
  • Security auditing
  • Compliance (CRA) New
  • Log in New

Bug bounty

  • Bug bounty
  • Leaderboard
  • Guidelines
  • Learn New
  • Report
  • Discord
  • Log in New

Use cases

  • Web developers
  • Webhosts New
  • Software vendors
  • WordPress
  • WooCommerce

Resources

  • Partners
  • Vulnerability database
  • Whitepaper 2026 New
  • Articles
  • Case studies New
  • Webinars New
  • Vulnerability statistics

Patchstack

  • About
  • Careers
  • Merch store
  • Media kit
  • LinkedIn
  • Facebook
  • X
  • Report Vulnerability
© 2026 Patchstack
DPA
Privacy Policy
Accessibility
Terms & Conditions