Remote Code Execution Vulnerability in oobabooga Text Generation Web UI
CVE-2025-12487
9.8CRITICAL
What is CVE-2025-12487?
A vulnerability in the oobabooga text-generation-webui application enables remote attackers to execute arbitrary code. This issue arises from inadequate validation in the handling of the 'trust_remote_code' parameter within the join endpoint, allowing an attacker to exploit the gap without authentication. By providing a malicious argument, an attacker could trigger the execution of code in the context of the service account, significantly compromising the security of affected installations.
Affected Version(s)
text-generation-webui 2.5
