CVE-2026-34526: SillyTavern: Incomplete IP validation in /api/search/visit allows SSRF via localhost and IPv6
(updated )
Server-side request forgery with partial restrictions. An authenticated user can force the server to fetch from internal hosts on default ports (80/443) using hostnames or IPv6 addresses that bypass the IP check. The full response body is returned. Lower severity than a fully unrestricted SSRF due to the port limitation.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-34526 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →