SillyTavern SSO Header Spoofing Authentication Bypass
Unvalidated Remote-User/X-Authentik-Username headers let any network client impersonate any user, including admins, when Authelia/Authentik SSO is enabled
SillyTavern, a self-hosted web UI for local LLM, image-generation, and TTS models, contains a critical authentication bypass in versions prior to 1.18.0. When an admin enables SSO integration with Authelia or Authentik (sso.autheliaAuth/sso.authentikAuth), the app blindly trusts the Remote-User or X-Authentik-Username HTTP headers to auto-login users, with no check that a real reverse proxy set them. Any client that can reach the SillyTavern port directly can forge these headers and log in as any user, including administrators, without a password — full account and data takeover. Fixed in 1.18.0, which adds an IP allowlist for SSO header trust.
Members only
Full technical analysis, attack chain, IOCs, and the defensive checklist are available to registered members — free to join.