← Back to CVE search

CVE-2026-35050

text-generation-webui

Description

text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.1.1, users can save extention settings in -py- format and in the app root directory. This allows to overwrite python files, for instance the -download-model.py- file could be overwritten. Then, this python file can be triggered to get executed from -Model- menu when requesting to download a new model. This vulnerability is fixed in 4.1.1.

CVSS 9.1EPSS 0.438%Risk 0.95
View source
Published
2026-04-06 18:16:42
Affected versions
<4.1.1
Type
Package
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H