Reliance on Untrusted Inputs in a Security Decision Affecting sillytavern package, versions <1.18.0


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Social Trends
Exploit Maturity
Proof of Concept
EPSS
0.22% (13th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-SILLYTAVERN-16691316
  • published14 May 2026
  • disclosed12 May 2026
  • creditspl::kirakira

Introduced: 12 May 2026

CVE-2026-44649  (opens in a new tab)
CWE-290  (opens in a new tab)
CWE-306  (opens in a new tab)
CWE-346  (opens in a new tab)
CWE-807  (opens in a new tab)

How to fix?

Upgrade sillytavern to version 1.18.0 or higher.

Overview

sillytavern is a LLM Frontend for Power Users

Affected versions of this package are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the headerUserLogin function. An attacker can gain unauthorized access to any user account, including administrators, by injecting crafted HTTP headers such as Remote-User or X-Authentik-Username when SSO is enabled.

Note: This is only exploitable if either sso.autheliaAuth: true or sso.authentikAuth: true is set in the configuration file.

CVSS Base Scores

version 4.0
version 3.1