๐Ÿ” CVE Alert

CVE-2026-26286

UNKNOWN 0.0

SillyTavern has Server-Side Request Forgery (SSRF) via Asset Download Endpoint that Allows Reading Internal Services

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. In versions prior to 1.16.0, a Server-Side Request Forgery (SSRF) vulnerability in the asset download endpoint allows authenticated users to make arbitrary HTTP requests from the server and read the full response body, enabling access to internal services, cloud metadata, and private network resources. The vulnerability has been patched in the version 1.16.0 by introducing a whitelist domain check for asset download requests. It can be reviewed and customized by editing the `whitelistImportDomains` array in the `config.yaml` file.

CWE CWE-918
Vendor sillytavern
Product sillytavern
Published Feb 19, 2026
Last Updated Feb 20, 2026
Stay Ahead of the Next One

Get instant alerts for sillytavern sillytavern

Be the first to know when new unknown vulnerabilities affecting sillytavern sillytavern are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

SillyTavern / SillyTavern
< 1.16.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/SillyTavern/SillyTavern/security/advisories/GHSA-cccp-94vg-j92r