Tag
high
advisory
text-generation-webui SSRF Vulnerability (CVE-2026-35486)
2 rules 1 TTP 1 CVE 2 IOCsThe text-generation-webui application before version 4.3 is vulnerable to server-side request forgery (SSRF) due to insufficient validation of user-supplied URLs by the superbooga and superboogav2 RAG extensions, potentially leading to credential theft and internal network reconnaissance.
ssrf
text-generation-webui
cve-2026-35486
cloud
2r
1t
1c
2i
critical
advisory
text-generation-webui Path Traversal Vulnerability (CVE-2026-35050)
2 rules 3 TTPs 1 CVE 1 IOCtext-generation-webui versions prior to 4.1.1 are vulnerable to path traversal, allowing a high-privileged user to overwrite Python files and achieve arbitrary code execution by triggering the 'download-model.py' file through the application's 'Model' menu.
path traversal
code execution
text-generation-webui
2r
3t
1c
1i