Impact
SillyTavern 1.17.0 and earlier expose a Server-Side Request Forgery (SSRF) weakness in the SearXNG search proxy path [S2][S6]. A user who can reach the web interface can cause the server to make outbound HTTP requests using an untrusted proxy base URL, which can expose data from services that the SillyTavern host can reach but the user should not access [S3].
Root Cause
The vulnerable implementation accepts the SearXNG proxy base URL from user-controlled request data and uses it for server-side fetches without restricting the destination to a trusted SearXNG origin [S2][S3]. SillyTavern 1.18.0 added Private Request Whitelisting as a server-side request filter for network-hosted deployments [S4][S6].
Remediation
Upgrade SillyTavern to 1.18.0 or newer [S2][S6]. For network-hosted instances, enable and configure Private Request Whitelisting, allowlist only trusted SearXNG origins, and keep the SillyTavern interface behind trusted-network or authenticated reverse-proxy access [S4][S5].
Covered by FixVibe
FixVibe's verified active scans flag SillyTavern deployments whose SearXNG search proxy can be made to fetch external URLs, reported as confirmed exposure.
