CVE-2026-44649
SillyTavern
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern accepts Remote-User (Authelia) and X-Authentik-Username (Authentik) HTTP headers to automatically log in users when SSO is configured. There is no validation that these headers originate from a trusted reverse proxy. Any network client that can reach the SillyTavern port directly can inject these headers and authenticate as any user, including administrators, without a password. Thi...
- CVSS
- 9.8
- EPSS
- 0.22% 12.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.30