FixVibe

high

SSRF in SillyTavern via SearXNG Search Proxy (CVE-2026-46372)

SillyTavern 1.17.0 and earlier have CVE-2026-46372, an SSRF in the SearXNG search proxy. FixVibe verified active scans flag deployments where the proxy can be used to fetch external URLs.

CVE-2026-46372GHSA-qg89-qwwh-5f3jGHSA-qg89-qwwh-5f3jCWE-918

Impact

SillyTavern 1.17.0 and earlier expose a Server-Side Request Forgery (SSRF) weakness in the SearXNG search proxy path [S2][S6]. A user who can reach the web interface can cause the server to make outbound HTTP requests using an untrusted proxy base URL, which can expose data from services that the SillyTavern host can reach but the user should not access [S3].

Root Cause

The vulnerable implementation accepts the SearXNG proxy base URL from user-controlled request data and uses it for server-side fetches without restricting the destination to a trusted SearXNG origin [S2][S3]. SillyTavern 1.18.0 added Private Request Whitelisting as a server-side request filter for network-hosted deployments [S4][S6].

Remediation

Upgrade SillyTavern to 1.18.0 or newer [S2][S6]. For network-hosted instances, enable and configure Private Request Whitelisting, allowlist only trusted SearXNG origins, and keep the SillyTavern interface behind trusted-network or authenticated reverse-proxy access [S4][S5].

Covered by FixVibe

FixVibe's verified active scans flag SillyTavern deployments whose SearXNG search proxy can be made to fetch external URLs, reported as confirmed exposure.