← Volver al buscador de CVEs

CVE-2026-35050

text-generation-webui

Descripción

text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.1.1, users can save extention settings in -py- format and in the app root directory. This allows to overwrite python files, for instance the -download-model.py- file could be overwritten. Then, this python file can be triggered to get executed from -Model- menu when requesting to download a new model. This vulnerability is fixed in 4.1.1.

CVSS 9.1EPSS 0.438%Riesgo 0.95
Ver fuente
Publicación
2026-04-06 18:16:42
Versiones afectadas
<4.1.1
Tipo
Package
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H