CVE-2026-44649
SillyTavern, a user interface for interacting with AI models, contains a flaw in how it handles single sign-on (SSO) authentication headers. If certain SSO settings are enabled, the application fails to verify that authentication headers come from a trusted source.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users running SillyTavern version 1.18.0 or earlier who have enabled Authelia or Authentik SSO in their config.yaml file.
Real-world impact
An attacker who can reach the SillyTavern network port can impersonate any user, including administrators, by injecting specific HTTP headers. This allows them to bypass password requirements and gain full control over the application.
Why this severity
This is a critical vulnerability because it allows an unauthenticated attacker to gain full administrative access remotely without needing a password.
What to do about it
- 01Upgrade SillyTavern to version 1.18.0 or later.
NVD-referenced vendor advisory
Timeline
- May 29, 2026 · May 29, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 22, 2026 · 13d agoAdvisory updatedThe NVD record was last revised.
- Jul 25, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.