PT-2025-44566 · Unknown · Oobabooga Text-Generation-Webui
Published
2025-10-30
·
Updated
2025-11-10
·
CVE-2025-12488
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
oobabooga text-generation-webui versions prior to 2.5
Description
The software is susceptible to a remote code execution issue stemming from insufficient validation of user-supplied input. Specifically, the
trust remote code parameter within the load endpoint is not properly validated before being used to load a model. This allows attackers to execute code in the context of the service account without authentication. The vulnerable parameter is trust remote code. The affected API endpoint is /load.Recommendations
Disable the
trust remote code functionality.
Restrict access to the /load API endpoint.Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oobabooga Text-Generation-Webui