Text Generation Web UI是oobabooga个人开发者的一个本地AI的UI界面。 Text Generation Web UI 4.3之前版本存在路径遍历漏洞,该漏洞源于load_preset函数中存在未经身份验证的路径遍历漏洞,可能导致读取服务器文件系统上的任何.yaml文件,并将解析后的YAML键值对(包括密码、API密钥、连接字符串)返回到API响应中。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| oobabooga | text-generation-webui | < 4.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-35485 | 7.5 HIGH | text-generation-webui has a Path Traversal in load_grammar() — arbitrary file read without |
| CVE-2026-35486 | 7.5 HIGH | text-generation-webui has a SSRF in superbooga/superboogav2 extensions — no URL validation |
| CVE-2026-35487 | 5.3 MEDIUM | text-generation-webui has a Path Traversal in load_prompt() — .txt file read without authe |
| CVE-2026-35483 | 5.3 MEDIUM | text-generation-webui has a Path Traversal in load_template() — .jinja/.yaml/.yml file rea |
No comments yet