1.18.0
3 years ago
29 days ago
Known vulnerabilities in the sillytavern package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
sillytavern is a LLM Frontend for Power Users Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) in SearXNG search proxy via unvalidated How to fix Server-side Request Forgery (SSRF)? Upgrade | <1.18.0 |
sillytavern is a LLM Frontend for Power Users Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the Note: This is only exploitable if the server is accessible over a network and the private request filter is not enabled and properly configured. How to fix Server-side Request Forgery (SSRF)? Upgrade | <1.18.0 |
sillytavern is a LLM Frontend for Power Users Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the How to fix Cross-site Scripting (XSS)? Upgrade | <1.18.0 |
sillytavern is a LLM Frontend for Power Users Affected versions of this package are vulnerable to Insufficient Session Expiration due to the failure to invalidate existing sessions after a password change. An attacker can maintain unauthorized access to an account by reusing a previously stolen session cookie, even after the legitimate user resets their password. How to fix Insufficient Session Expiration? Upgrade | <1.18.0 |
sillytavern is a LLM Frontend for Power Users Affected versions of this package are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the Note: This is only exploitable if either How to fix Reliance on Untrusted Inputs in a Security Decision? Upgrade | <1.18.0 |
sillytavern is a LLM Frontend for Power Users Affected versions of this package are vulnerable to Directory Traversal via the How to fix Directory Traversal? Upgrade | <1.18.0 |
sillytavern is a LLM Frontend for Power Users Affected versions of this package are vulnerable to Directory Traversal via the How to fix Directory Traversal? Upgrade | <1.17.0 |
sillytavern is a LLM Frontend for Power Users Affected versions of this package are vulnerable to External Control of File Name or Path via the How to fix External Control of File Name or Path? Upgrade | <1.17.0 |
sillytavern is a LLM Frontend for Power Users Affected versions of this package are vulnerable to Directory Traversal via the How to fix Directory Traversal? Upgrade | <1.17.0 |
sillytavern is a LLM Frontend for Power Users Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) in the How to fix Server-side Request Forgery (SSRF)? Upgrade | <1.17.0 |
sillytavern is a LLM Frontend for Power Users Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the asset download endpoint. An attacker can access internal services, cloud metadata, and private network resources by sending crafted HTTP requests from the server. How to fix Server-side Request Forgery (SSRF)? Upgrade | <1.16.0 |
sillytavern is a LLM Frontend for Power Users Affected versions of this package are vulnerable to Improper Verification of Source of a Communication Channel via improper validation of the Note: The vulnerability has been patched by introducing a server configuration setting that enables a validation of host names in inbound HTTP requests; However, the setting is disabled by default to maintain backwards compatibility. Users are recommended to review their server configurations and apply necessary changes to their setup. How to fix Improper Verification of Source of a Communication Channel? Upgrade | <1.13.4 |