SillyTavern 1.12.13 至 1.19.0 版本存在一个拒绝服务(DoS)漏洞,允许未经认证的远程攻击者通过耗尽系统资源来造成服务不可用。该漏洞的根本原因在于 body-parser 中间件在身份认证和访问白名单检查之前就已执行。攻击者可以发送体积庞大(最大达 500 MB)或经过压缩的 JSON 或 urlencoded 格式的请求体,并可并发发送,从而耗尽服务器的内存和 CPU 资源,导致服务拒绝。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SillyTavern | SillyTavern | 1.12.13≤ 1.19.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SillyTavern | SillyTavern | 1.12.13 ~ 1.19.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet