OVERVIEW CVE-2026-35483 is a path traversal vulnerability affecting text-generation-webui, an open-source web interface for running Large Language Models, in versions prior to 4.3. An unauthenticated attacker can exploit the load_template() function to read arbitrary files with .jinja, .jinja2, .yaml, or .yml extensions from the server filesystem, with .jinja files returned in full and .yaml files having parsed keys extracted. SEVERITY The vulnerability has a CVSS score of 5.3 (Medium) with a network-based attack vector requiring no authentication, low attack complexity, and no user interaction. The impact is limited to confidentiality, allowing unauthorized information disclosure without affecting system integrity or availability. The EPSS score of 0.00064 indicates this is a relatively low-probability exploit compared to other known vulnerabilities, ranking higher than only 0.2% of all CVEs in exploitability likelihood. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, as indicated by the inactive Hot List status and absence from the Known Exploited Vulnerabilities (KEV) catalog. No publicly available exploit code has been reported. However, the straightforward nature of path traversal attacks and the vulnerability's inherent simplicity suggests exploitation remains a concern for unpatched deployments. Organizations running text-generation-webui prior to version 4.3 should prioritize patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.3CPE matchmatch criteria | cpe:2.3:a:oobabooga:textgen:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.