S4E just found a high-severity finding from cve-2025-68645 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated May 20, 2026

CVE-2026-46372 Scanner

CVE-2026-46372 Scanner - Server-Side-Request-Forgery (SSRF) vulnerability in SillyTavern

Est. Time~1 minutes
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.9k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-46372
8.5
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient.

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern exposes /api/search/searxng, which accepts attacker-controlled baseUrl and uses it directly to build outbound server-side fetches. An authenticated low-privilege user can point baseUrl at an internal or loopback HTTP service and receive the /search response body. This vulnerability is fixed in 1.18.0.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
SillyTavernby SillyTavern
< 1.18.0
Updated Aug 21, 2026View on NVD →
Detail

SillyTavern is a popular software application used in various settings for managing and organizing events or social gatherings. It is primarily implemented by event coordinators, party planners, or venue managers seeking an efficient tool for handling guest lists, schedules, and other logistics. This software helps streamline communication and organization, which enhances the overall experience for both organizers and attendees. SillyTavern provides a user-friendly interface, enabling users to quickly set up and modify events as needed. The software is often deployed over networks to allow seamless collaboration among multiple users. SillyTavern also offers various integrations to enhance its functionality, making it a versatile tool for managing events.

The vulnerability detected in SillyTavern is a Server-Side-Request-Forgery (SSRF) flaw. SSRF vulnerabilities occur when an attacker can trick a server into sending a crafted request to another server, including internal or protected services. In this case, the SSRF vulnerability affects SillyTavern versions up to and including 1.17.0, due to the exposure of the /api/search/searxng endpoint. This endpoint improperly handles attacker-controlled baseUrl parameters, which are then used to build outbound server-side requests. Authenticated low-privileged users can exploit this to direct requests towards internal services and access sensitive data.

Technically, this vulnerability arises from the lack of adequate validation on the baseUrl parameter within the /api/search/searxng endpoint. By manipulating this parameter, attackers can craft requests targeting internal IP addresses or cloud metadata endpoints. This unintended behavior allows attackers to bypass typical access controls and extract potentially sensitive information. Additional security flaws may be present if hosting over a network without proper configurations. When exploited, the vulnerability grants unauthorized access to internal network resources or secured environments, highlighting a serious security concern.

The possible effects of exploiting the SSRF vulnerability in SillyTavern can be severe. An attacker can gain unauthorized access to internal systems and data, potentially exposing sensitive information such as private IP addresses, configuration files, or database contents. This could lead to further exploitation, including lateral movement within a network or service disruption. Additionally, the disclosure of cloud metadata endpoints can facilitate subsequent attacks, such as privilege escalation or data exfiltration. Organizations utilizing vulnerable versions of SillyTavern are at a heightened risk of compromise and should urgently address the issue.

REFERENCES

Solution Advice
  • Upgrade SillyTavern to version 1.18.0 or later to benefit from security enhancements.
  • Enable and properly configure the Private Request Whitelisting filter when hosting over a network to prevent unauthorized access.
  • Conduct comprehensive security reviews and apply any additional patches as needed.
  • Implement network segmentation to minimize access to sensitive internal resources from exposed endpoints.
  • Continuously monitor server logs for unusual activities that could indicate exploitation attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.