Critical Flaw CVE-2025-59159 (CVSS 9.7) in SillyTavern Allows Full Remote Control of Local AI Instances
ID: cad2fcca-8266-5616-a9de-beb807edef7c
STIX ID: report--cad2fcca-8266-5616-a9de-beb807edef7c
Feed Name: securityonline.info
A critical DNS rebinding vulnerability (CVE-2025-59159, CVSS 9.7) in SillyTavern's web UI can let remote attackers trick a browser into treating the local SillyTavern instance as a trusted domain, enabling full control over the instance (reading chats, stealing API keys, installing extensions, injecting phishing HTML). The advisory provides a PoC demonstrating how a malicious webpage can rebind DNS to 127.0.0.1 to exploit the flaw and notes a patch in SillyTavern 1.13.4 that introduces an optional host whitelist which must be enabled by users to mitigate the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
