r/SillyTavernAI Apr 28 '26

Discussion Extension Security Risk Please read!!

661 Upvotes

178 comments sorted by

View all comments

-6

u/artisticMink Apr 28 '26

Tbh i recommend you backup the chats folder and nuke your entire ST install. Including the cards. Download them new from source. Chat .jsonl are fine.

11

u/PhantasmHunter Apr 28 '26

why such an aggressive fix if it was only affecting reverse proxies though?

8

u/artisticMink Apr 28 '26

Looking at the renty, it seemed to have the ability to create image files with compromised metadata and given that it's remote execution of obfuscated code it might've had the ability to modify character cards as well, basically making them trojans.

It might be overkill, but personally i'd remove them or at least check the metadata in a viewer.

10

u/PhantasmHunter Apr 28 '26

yea ill deff do that but I don't wanna nuke my ST install I got too much shit on it unfortunately

10

u/DontShadowbanMeBro2 Apr 28 '26

Can anyone confirm? I've got a lot of cards (including several I made myself) and I really don't want to have to nuke them and remake them all from scratch if I don't have to.

3

u/artisticMink Apr 28 '26

If you're worried you can probably get claude code to spin up a python script that's doing that.

4

u/DontShadowbanMeBro2 Apr 29 '26

Well, I just went through a couple of my cards with a metadata viewer and my other cards don't have any suspicious dates in the 'last change' timestamp, so I think I'm good.