{"id":"CVE-2026-44652","summary":"SillyTavern: SSRF vulnerability in the CORS proxy middleware","details":"SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, corsProxyMiddleware forwards req.params.url directly into fetch(url, ...). It only blocks circular requests to its own host and does not enforce destination allowlist or private/loopback restrictions, enabling SSRF. This vulnerability is fixed in 1.18.0.","aliases":["GHSA-ccfq-2454-f5xw"],"modified":"2026-07-23T03:56:12.499281395Z","published":"2026-05-29T17:43:07.425Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44652.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-918"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44652.json"},{"type":"ADVISORY","url":"https://github.com/SillyTavern/SillyTavern/security/advisories/GHSA-ccfq-2454-f5xw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44652"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/sillytavern/sillytavern","events":[{"introduced":"0"},{"fixed":"51ad27fb86d39a3daca3adaa970375c9670c12df"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.18.0"}],"source":"AFFECTED_FIELD"}}],"versions":["1.17.0","1.16.0","1.15.0","1.14.0","1.13.5","1.13.4","1.13.3","1.13.2","1.13.1","1.13.0","1.12.14","1.12.13","1.12.12","1.12.11","1.12.10","1.12.9","1.12.8","1.12.7","1.12.6","1.12.5","1.12.4","1.12.3","1.12.2","1.12.1","1.12.0-6","1.12.0","1.11.8","1.11.7","1.11.6","1.11.5","1.11.4-1","1.11.4","1.11.3","1.11.2","1.11.1","1.11.0","1.10.10","1.10.9","1.10.8","1.10.7","1.10.6","1.10.5","1.10.4","1.10.3","1.10.2","1.10.1","1.10.0","1.9.7","1.9.6","1.9.5","1.9.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44652.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}