PT-2026-30859 · Unknown+1 · Superbooga+3

Programsurf

+2

·

Published

2026-04-07

·

Updated

2026-04-07

·

CVE-2026-35486

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions text-generation-webui versions prior to 4.3
Description text-generation-webui is an open-source web interface for running Large Language Models. The superbooga and superboogav2 RAG extensions, in versions prior to 4.3, retrieve user-provided URLs using requests.get() without any validation. This includes a lack of scheme checking, IP filtering, or hostname allowlisting. This allows an attacker to access cloud metadata endpoints, potentially stealing IAM credentials and probing internal services. The retrieved content is then exfiltrated through the RAG pipeline.
Recommendations Update to version 4.3 or later.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-35486

Affected Products

Requests
Superbooga
Superboogav2
Text-Generation-Webui