Oobabooga develops a text-generation web interface that provides a locally deployable platform for large language model inference, with a narrow but concentrated product footprint. Its vulnerability profile centers on input-handling and server-interaction flaws, particularly path traversal and server-side request forgery, which reflect the surface-area risk inherent to a web-facing application that bridges user input and backend resource access. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Oobabooga over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-35050HIGH text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.1.1, users can save extention settings in "py" format and in the app root direct | Apr 6, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-35485HIGH text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticated path traversal vulnerability in load_grammar() allows read | Apr 7, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-35486HIGH text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, he superbooga and superboogav2 RAG extensions fetch user-supplied URLs via re | Apr 7, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-35487MEDIUM text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticated path traversal vulnerability in load_prompt() allows readi | Apr 7, 2026 | 5.3 | 20 | NO | NO |
CVE-2026-35484MEDIUM text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticated path traversal vulnerability in load_preset() allows readi | Apr 7, 2026 | 5.3 | 20 | NO | NO |
CVE-2026-35483MEDIUM text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticated path traversal vulnerability in load_template() allows rea | Apr 7, 2026 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Oobabooga.
Media articles that mention a CVE ID that affects a product developed by Oobabooga — matched by CVE ID, not by vendor name.