PT-2026-30687 · Unknown · Text-Generation-Webui

·

CVE-2026-35050

·

Published

2026-04-06

·

Updated

2026-04-06

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions text-generation-webui versions prior to 4.1.1
Description text-generation-webui is an open-source web interface for running Large Language Models. Prior to version 4.1.1, users could save extension settings in '.py' format within the application root directory, enabling overwriting of Python files such as 'download-model.py'. This overwritten file could then be triggered for execution through the 'Model' menu when a new model download was requested.
Recommendations Update to version 4.1.1 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35050
GHSA-JG96-P5P6-Q3CV

Affected Products

Text-Generation-Webui