Unauthenticated Path Traversal Vulnerability in Text Generation Web UI by Oobabooga
CVE-2026-35484
5.3MEDIUM
What is CVE-2026-35484?
The Text Generation Web UI, an open-source interface for deploying Large Language Models, has a path traversal vulnerability that allows unauthenticated users to access sensitive YAML configuration files on the server. This flaw, prior to version 4.3, enables attackers to retrieve key-value pairs from these files, exposing sensitive information such as passwords, API keys, and connection strings. The vulnerability has been mitigated in version 4.3.
Affected Version(s)
text-generation-webui < 4.3
