Text Generation Web UI是oobabooga个人开发者的一个本地AI的UI界面。 Text Generation Web UI 4.3之前版本存在代码问题漏洞,该漏洞源于superbooga和superboogav2 RAG扩展通过requests.get获取用户提供的URL时未进行任何验证,可能导致攻击者访问云元数据端点、窃取IAM凭据并探测内部服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| oobabooga | text-generation-webui | < 4.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-35485 | 7.5 HIGH | text-generation-webui has a Path Traversal in load_grammar() — arbitrary file read without |
| CVE-2026-35487 | 5.3 MEDIUM | text-generation-webui has a Path Traversal in load_prompt() — .txt file read without authe |
| CVE-2026-35483 | 5.3 MEDIUM | text-generation-webui has a Path Traversal in load_template() — .jinja/.yaml/.yml file rea |
| CVE-2026-35484 | 5.3 MEDIUM | text-generation-webui has a Path Traversal in load_preset() — .yaml file read without auth |
No comments yet