Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 28 Apr 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oobabooga textgen
|
|
| CPEs | cpe:2.3:a:oobabooga:textgen:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oobabooga textgen
|
Wed, 08 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oobabooga
Oobabooga text-generation-webui |
|
| Vendors & Products |
Oobabooga
Oobabooga text-generation-webui |
Wed, 08 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 07 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticated path traversal vulnerability in load_preset() allows reading any .yaml file on the server filesystem. The parsed YAML key-value pairs (including passwords, API keys, connection strings) are returned in the API response. This vulnerability is fixed in 4.3. | |
| Title | text-generation-webui has a Path Traversal in load_preset() — .yaml file read without authentication | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-08T14:46:53.620Z
Reserved: 2026-04-02T20:49:44.454Z
Link: CVE-2026-35484
Updated: 2026-04-08T14:46:47.165Z
Status : Analyzed
Published: 2026-04-07T15:17:45.530
Modified: 2026-04-28T21:39:46.813
Link: CVE-2026-35484
No data.
OpenCVE Enrichment
Updated: 2026-04-08T19:48:41Z