PT-2025-44565 · Unknown · Oobabooga Text-Generation-Webui
Published
2025-10-30
·
Updated
2025-11-10
·
CVE-2025-12487
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
oobabooga text-generation-webui version 2.5
Description
The software contains a remote code execution issue stemming from reliance on untrusted inputs. This allows attackers to execute arbitrary code on affected systems without authentication. The issue is related to the
trust remote code parameter within the join endpoint. Insufficient validation of user-supplied arguments before loading a model enables an attacker to execute code in the context of the service account.Recommendations
Restrict access to the join endpoint.
Disable the
trust remote code parameter.Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oobabooga Text-Generation-Webui