PT-2026-30857 · Oobabooga · Text-Generation-Webui

Published

2026-04-07

·

Updated

2026-04-07

·

CVE-2026-35484

CVSS v3.1

5.3

Medium

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticated path traversal vulnerability in load preset() allows reading any .yaml file on the server filesystem. The parsed YAML key-value pairs (including passwords, API keys, connection strings) are returned in the API response. This vulnerability is fixed in 4.3.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-35484

Affected Products

Text-Generation-Webui