<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 11:58:25 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-323666</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-323666</link>
      <description>EUVD-2026-323666</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-323666</guid>
    </item>
    <item>
      <title>fkie_cve-2026-44649</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44649</link>
      <description>&lt;p&gt;SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern accepts Remote-User (Authelia) and X-Authentik-Username (Authentik) HTTP headers to automatically log in users when SSO is configured. There is no validation that these headers originate from a trusted reverse proxy. Any network client that can reach the SillyTavern port directly can inject these headers and authenticate as any user, including administrators, without a password. This vulnerability is exploitable only when sso.autheliaAuth: true or sso.authentikAuth: true is set in config.yaml (both default to false). This vulnerability is fixed in 1.18.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern accepts Remote-User (Authelia) and X-Authentik-Username (Authentik) HTTP headers to automatically log in users when SSO is configured. There is no validation that these headers originate from a trusted reverse proxy. Any network client that can reach the SillyTavern port directly can inject these headers and authenticate as any user, including administrators, without a password. This vulnerability is exploitable only when sso.autheliaAuth: true or sso.authentikAuth: true is set in config.yaml (both default to false). This vulnerability is fixed in 1.18.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-44649</guid>
    </item>
    <item>
      <title>GHSA-gxx6-h3g6-vwjh — SillyTavern has Authentication Bypass via SSO Header Injection</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gxx6-h3g6-vwjh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: sillytavern&lt;/p&gt;
&lt;p&gt;## Resolution&lt;/p&gt;
&lt;p&gt;SillyTavern 1.18.0 now includes a configuration option to limit which IP addresses can authorize using SSO headers, limiting to just loopback addresses by default. A setting can be customized according to user&amp;#39;s needs.&lt;/p&gt;
&lt;p&gt;Documentation: https://docs.sillytavern.app/administration/sso/&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;SillyTavern accepts `Remote-User` (Authelia) and `X-Authentik-Username` (Authentik) HTTP
headers to automatically log in users when SSO is configured. There is no validation that
these headers originate from a trusted reverse proxy. Any network client that can reach
the SillyTavern port directly can inject these headers and authenticate as any user,
including administrators, without a password. This vulnerability is exploitable only when `sso.autheliaAuth: true` or
`sso.authentikAuth: true` is set in `config.yaml` (both default to `false`).&lt;/p&gt;
&lt;p&gt;### Detials&lt;/p&gt;
&lt;p&gt;SillyTavern implements header-based SSO for Authelia and Authentik. When enabled, the
`tryAutoLogin` function (called on every request to `/login`) invokes `headerUserLogin`,
which reads an HTTP header set by the upstream proxy and automatically creates an
authenticated session for the matching user:&lt;/p&gt;
&lt;p&gt;`src/users.js:779-801`:&lt;/p&gt;
&lt;p&gt;```js
async function headerUserLogin(request, header = &amp;#39;Remote-User&amp;#39;) {
    if (!request.session) { return false; }&lt;/p&gt;
&lt;p&gt;const remoteUser = request.get(header);  // reads any header from any client
    if (!remoteUser) { return false; }&lt;/p&gt;
&lt;p&gt;const userHandles = await getAllUserHandles();
    for (…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: sillytavern&lt;/p&gt;
&lt;p&gt;## Resolution&lt;/p&gt;
&lt;p&gt;SillyTavern 1.18.0 now includes a configuration option to limit which IP addresses can authorize using SSO headers, limiting to just loopback addresses by default. A setting can be customized according to user&amp;#39;s needs.&lt;/p&gt;
&lt;p&gt;Documentation: https://docs.sillytavern.app/administration/sso/&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;SillyTavern accepts `Remote-User` (Authelia) and `X-Authentik-Username` (Authentik) HTTP
headers to automatically log in users when SSO is configured. There is no validation that
these headers originate from a trusted reverse proxy. Any network client that can reach
the SillyTavern port directly can inject these headers and authenticate as any user,
including administrators, without a password. This vulnerability is exploitable only when `sso.autheliaAuth: true` or
`sso.authentikAuth: true` is set in `config.yaml` (both default to `false`).&lt;/p&gt;
&lt;p&gt;### Detials&lt;/p&gt;
&lt;p&gt;SillyTavern implements header-based SSO for Authelia and Authentik. When enabled, the
`tryAutoLogin` function (called on every request to `/login`) invokes `headerUserLogin`,
which reads an HTTP header set by the upstream proxy and automatically creates an
authenticated session for the matching user:&lt;/p&gt;
&lt;p&gt;`src/users.js:779-801`:&lt;/p&gt;
&lt;p&gt;```js
async function headerUserLogin(request, header = &amp;#39;Remote-User&amp;#39;) {
    if (!request.session) { return false; }&lt;/p&gt;
&lt;p&gt;const remoteUser = request.get(header);  // reads any header from any client
    if (!remoteUser) { return false; }&lt;/p&gt;
&lt;p&gt;const userHandles = await getAllUserHandles();
    for (…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gxx6-h3g6-vwjh</guid>
    </item>
  </channel>
</rss>
