pkg:npm/sillytavern
11 total CVEsCRITICAL3HIGH4MEDIUM2
✅ Check your installed version
All known vulnerabilities
- from 0, < 1.18.0
- from 0, < 1.13.4
- from 0, < 1.18.0
- from 0, < 1.18.0
- HIGH8.3CVE-2026-34524SillyTavern: Path Traversal in `/api/chats/export` and `/api/chats/delete` allows arbitrary file read/delete within user data rootfrom 0, < 1.17.0
- HIGH8.1CVE-2026-34522SillyTavern has a path traversal in `/api/chats/import` allows arbitrary file write outside intended chat directoryfrom 0, < 1.17.0
- HIGH7.5CVE-2026-44648SillyTavern: Existing sessions are not invalidated after password change, allowing session reuse and account takeoverfrom 0, < 1.18.0
- from 0, < 1.17.0
- MEDIUM5.0CVE-2026-34526SillyTavern: Incomplete IP validation in /api/search/visit allows SSRF via localhost and IPv6from 0, < 1.17.0
- from 0, < 1.18.0
- from 0, < 1.18.0