PT-2026-30856 · Oobabooga · Text-Generation-Webui

Published

2026-04-07

·

Updated

2026-04-07

·

CVE-2026-35483

CVSS v3.1

5.3

Medium

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticated path traversal vulnerability in load template() allows reading files with .jinja, .jinja2, .yaml, or .yml extensions from anywhere on the server filesystem. For .jinja files the content is returned verbatim; for .yaml files a parsed key is extracted. This vulnerability is fixed in 4.3.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-35483

Affected Products

Text-Generation-Webui