SillyTavern
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 7 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from October 6, 2025 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →SillyTavern 1.12.13 through 1.19.0 Pre-Authentication Denial of Service via Body Parsing
SillyTavern: Incomplete IP validation in /api/search/visit allows SSRF via localhost and IPv6
SillyTavern: Path traversal in `/api/chats/export` and `/api/chats/delete` allows arbitrary file read/delete within user data root
SillyTavern: Path traversal allows file existence oracle
SillyTavern: Path traversal in `/api/chats/import` allows arbitrary file write outside intended chat directory
SillyTavern has Server-Side Request Forgery (SSRF) via Asset Download Endpoint that Allows Reading Internal Services
SillyTavern Web Interface Vulnerable to DNS Rebinding
Monitor SillyTavern in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.