#VU117873 Reliance on Untrusted Inputs in a Security Decision in Text Generation Web UI - CVE-2025-12488
Published: October 31, 2025
Text Generation Web UI
oobabooga
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to lack of proper validation of a user-supplied argument before using it to load a model within the handling of the trust_remote_code parameter provided to the load endpoint. A remote attacker can execute arbitrary code on the system.