CVE-2026-26286 | SillyTavern up to 1.15.x Asset Download Endpoint server-side request forgery (GHSA-cccp-94vg-j92r)
A vulnerability, which was classified as critical, was found in SillyTavern up to 1.15.x. The affected element is an unknown function of the component Asset Download Endpoint. The manipulation results in server-side request forgery.
This vulnerability is cataloged as CVE-2026-26286. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.