Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Vulnerability List
Found 6 results
CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2026-34526 SillyTavern: Incomplete IP validation in /api/search/visit allows SSRF via localhost and IPv6 SillyTavernSillyTavern Medium 5.0 2026-04-02 17:16:56 Deep Dive
CVE-2026-34524 SillyTavern: Path traversal in `/api/chats/export` and `/api/chats/delete` allows arbitrary file read/delete within user data root SillyTavernSillyTavern High 8.3 2026-04-02 17:15:23 Deep Dive
CVE-2026-34523 SillyTavern: Path traversal allows file existence oracle SillyTavernSillyTavern Medium 5.3 2026-04-02 17:14:32 Deep Dive
CVE-2026-34522 SillyTavern: Path traversal in `/api/chats/import` allows arbitrary file write outside intended chat directory SillyTavernSillyTavern High 8.1 2026-04-02 17:13:44 Deep Dive
CVE-2026-26286 SillyTavern has Server-Side Request Forgery (SSRF) via Asset Download Endpoint that Allows Reading Internal Services SillyTavernSillyTavern 高危 -2026-02-19 21:02:22 Deep Dive
CVE-2025-59159 SillyTavern Web Interface Vulnerable to DNS Rebinding SillyTavernSillyTavern Critical 9.6 2025-10-06 15:31:46 Deep Dive