Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 09 Apr 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oobabooga text Generation Web Ui
|
|
| CPEs | cpe:2.3:a:oobabooga:text_generation_web_ui:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oobabooga text Generation Web Ui
|
Wed, 08 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oobabooga
Oobabooga text-generation-webui |
|
| Vendors & Products |
Oobabooga
Oobabooga text-generation-webui |
Tue, 07 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 07 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticated path traversal vulnerability in load_prompt() allows reading any .txt file on the server filesystem. The file content is returned verbatim in the API response. This vulnerability is fixed in 4.3. | |
| Title | text-generation-webui has a Path Traversal in load_prompt() — .txt file read without authentication | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-07T18:14:46.381Z
Reserved: 2026-04-02T20:49:44.454Z
Link: CVE-2026-35487
Updated: 2026-04-07T18:14:41.731Z
Status : Analyzed
Published: 2026-04-07T16:16:26.853
Modified: 2026-04-09T18:46:11.693
Link: CVE-2026-35487
No data.
OpenCVE Enrichment
Updated: 2026-04-10T09:41:31Z