SillyTavern 1.18.0 added a generic server-side request filter (Private Request Whitelisting). Since we expect users to use the application in a trusted environment, the filter is disabled by default, however it is strongly advised to be enabled and properly configured when an instance is being hosted over a network, as suggested by a console warning message and an officially published security checklist for administrators.
Documentation:
Since the request filter applies to the entire application, no SSRF vulnerabilities against individual endpoints will be accepted, unless it has been proven that a properly configured and enabled filter can be bypassed in an undocumented way. Only advisories disclosed before the 1.18.0 release will be posted if their concern is SSRF.
src/middleware/corsProxy.js:31corsProxyMiddleware forwards req.params.url directly into fetch(url, ...). It only blocks circular requests to its own host and does not enforce destination allowlist or private/loopback restrictions, enabling SSRF.
GET /proxy/:url(*)SSRF in optional CORS proxysrc/middleware/corsProxy.js:31src/middleware/corsProxy.js:31This issue can be used to pivot network access and reach unintended internal resources.
An attacker may access internal network services or metadata endpoints and exfiltrate sensitive responses.
{
"cwe_ids": [
"CWE-918"
],
"github_reviewed": true,
"github_reviewed_at": "2026-05-12T22:24:05Z",
"nvd_published_at": "2026-05-29T19:16:25Z",
"severity": "MODERATE"
}