logo

Critical Flaw CVE-2025-59159 (CVSS 9.7) in SillyTavern Allows Full Remote Control of Local AI Instances

ID: cad2fcca-8266-5616-a9de-beb807edef7c

STIX ID: report--cad2fcca-8266-5616-a9de-beb807edef7c

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2025-10-07

Date Updated: 2026-04-22

Author: Ddos

...
...

A critical DNS rebinding vulnerability (CVE-2025-59159, CVSS 9.7) in SillyTavern's web UI can let remote attackers trick a browser into treating the local SillyTavern instance as a trusted domain, enabling full control over the instance (reading chats, stealing API keys, installing extensions, injecting phishing HTML). The advisory provides a PoC demonstrating how a malicious webpage can rebind DNS to 127.0.0.1 to exploit the flaw and notes a patch in SillyTavern 1.13.4 that introduces an optional host whitelist which must be enabled by users to mitigate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.