PT-2025-41812 · Unknown · Text-Generation-Webui
J1W0N-1209
+2
·
Published
2025-10-13
·
Updated
2025-10-13
·
CVE-2025-62364
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
text-generation-webui versions through 3.13
Description
text-generation-webui is a web interface for running Large Language Models. A Local File Inclusion issue exists in the character picture upload feature. An attacker can upload a text file containing a symbolic link to an arbitrary file path. The application follows the symbolic link and serves the contents of the targeted file through the web interface. This allows an unauthenticated attacker to read sensitive files on the server, potentially exposing system configurations and credentials.
Recommendations
Update to version 3.14 or later.
Exploit
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Text-Generation-Webui