PT-2026-30860 · Oobabooga · Text-Generation-Webui

Published

2026-04-07

·

Updated

2026-04-07

·

CVE-2026-35487

CVSS v3.1

5.3

Medium

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticated path traversal vulnerability in load prompt() allows reading any .txt file on the server filesystem. The file content is returned verbatim in the API response. This vulnerability is fixed in 4.3.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-35487

Affected Products

Text-Generation-Webui