
⚠️⚠️ CVE-2026-44649 (CVSS 9.8): SillyTavern auth bypass / account takeover via spoofable SSO headers (Remote-User / X-Authentik-Username) when Authelia/Authentik SSO is enabled; upgrade to 1.18.0+. 🔥PoC: https://github.com/SillyTavern/SillyTavern/security/advisories/GHSA-gxx6-h3g6-vwjh#poc 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJTaWxseVRhdmVybiI%3D 🎯29.2K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="SillyTavern" 🔖Refer: https://github.com/SillyTavern/SillyTavern/security/advisories/GHSA-gxx6-h3g6-vwjh #OSINT #FOFA #CyberSecurity #Vulnerability
Post summary
CVE-2026-44649 reveals a severe auth bypass in SillyTavern via spoofable SSO headers, provides a PoC link, and urges users to upgrade to version 1.18.0+.



