Text Generation Web UI是oobabooga个人开发者的一个本地AI的UI界面。 Text Generation Web UI 4.3之前版本存在路径遍历漏洞,该漏洞源于load_template函数中存在未经身份验证的路径遍历漏洞,可能导致读取服务器文件系统上任何位置具有.jinja、.jinja2、.yaml或.yml扩展名的文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| oobabooga | text-generation-webui | < 4.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-35485 | 7.5 HIGH | text-generation-webui has a Path Traversal in load_grammar() — arbitrary file read without |
| CVE-2026-35486 | 7.5 HIGH | text-generation-webui has a SSRF in superbooga/superboogav2 extensions — no URL validation |
| CVE-2026-35487 | 5.3 MEDIUM | text-generation-webui has a Path Traversal in load_prompt() — .txt file read without authe |
| CVE-2026-35484 | 5.3 MEDIUM | text-generation-webui has a Path Traversal in load_preset() — .yaml file read without auth |
No comments yet