<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T11:01:48.635857+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-323666</id>
    <title>EUVD-2026-323666</title>
    <updated>2026-10-07T11:01:48.696419+00:00</updated>
    <content>EUVD-2026-323666</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-323666"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44649</id>
    <title>fkie_cve-2026-44649</title>
    <updated>2026-10-07T11:01:48.696473+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern accepts Remote-User (Authelia) and X-Authentik-Username (Authentik) HTTP headers to automatically log in users when SSO is configured. There is no validation that these headers originate from a trusted reverse proxy. Any network client that can reach the SillyTavern port directly can inject these headers and authenticate as any user, including administrators, without a password. This vulnerability is exploitable only when sso.autheliaAuth: true or sso.authentikAuth: true is set in config.yaml (both default to false). This vulnerability is fixed in 1.18.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-44649"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gxx6-h3g6-vwjh</id>
    <title>GHSA-gxx6-h3g6-vwjh — SillyTavern has Authentication Bypass via SSO Header Injection</title>
    <updated>2026-10-07T11:01:48.696530+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: sillytavern</p>
<p>## Resolution</p>
<p>SillyTavern 1.18.0 now includes a configuration option to limit which IP addresses can authorize using SSO headers, limiting to just loopback addresses by default. A setting can be customized according to user's needs.</p>
<p>Documentation: https://docs.sillytavern.app/administration/sso/</p>
<p>## Summary</p>
<p>SillyTavern accepts `Remote-User` (Authelia) and `X-Authentik-Username` (Authentik) HTTP
headers to automatically log in users when SSO is configured. There is no validation that
these headers originate from a trusted reverse proxy. Any network client that can reach
the SillyTavern port directly can inject these headers and authenticate as any user,
including administrators, without a password. This vulnerability is exploitable only when `sso.autheliaAuth: true` or
`sso.authentikAuth: true` is set in `config.yaml` (both default to `false`).</p>
<p>### Detials</p>
<p>SillyTavern implements header-based SSO for Authelia and Authentik. When enabled, the
`tryAutoLogin` function (called on every request to `/login`) invokes `headerUserLogin`,
which reads an HTTP header set by the upstream proxy and automatically creates an
authenticated session for the matching user:</p>
<p>`src/users.js:779-801`:</p>
<p>```js
async function headerUserLogin(request, header = 'Remote-User') {
    if (!request.session) { return false; }</p>
<p>const remoteUser = request.get(header);  // reads any header from any client
    if (!remoteUser) { return false; }</p>
<p>const userHandles = await getAllUserHandles();
    for (…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gxx6-h3g6-vwjh"/>
  </entry>
</feed>
