Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 24 Apr 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oobabooga textgen
|
|
| CPEs | cpe:2.3:a:oobabooga:textgen:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oobabooga textgen
|
Wed, 08 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oobabooga
Oobabooga text-generation-webui |
|
| Vendors & Products |
Oobabooga
Oobabooga text-generation-webui |
Tue, 07 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 07 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticated path traversal vulnerability in load_template() allows reading files with .jinja, .jinja2, .yaml, or .yml extensions from anywhere on the server filesystem. For .jinja files the content is returned verbatim; for .yaml files a parsed key is extracted. This vulnerability is fixed in 4.3. | |
| Title | text-generation-webui has a Path Traversal in load_template() — .jinja/.yaml/.yml file read without authentication | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-07T17:55:20.808Z
Reserved: 2026-04-02T20:49:44.454Z
Link: CVE-2026-35483
Updated: 2026-04-07T17:55:17.956Z
Status : Analyzed
Published: 2026-04-07T15:17:45.377
Modified: 2026-04-24T15:15:43.870
Link: CVE-2026-35483
No data.
OpenCVE Enrichment
Updated: 2026-04-08T19:48:42Z