Relative Path Traversal in Text Generation Web UI - CVE-2025-62364

 

Relative Path Traversal in Text Generation Web UI - CVE-2025-62364

Published: April 24, 2026


Vulnerability identifier: #VU127414
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-62364
CWE-ID: CWE-23
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper neutralization of file paths in the character picture upload feature when processing an uploaded symbolic link file. A remote attacker can upload a crafted .txt file containing a symbolic link and access the uploaded file URL to disclose sensitive information.

The issue can expose server files such as system configuration files and credentials.


Affected software

Text Generation Web UI

How to mitigate CVE-2025-62364

Install security update from vendor's website.

Text Generation Web UI - update to 3.14

External References

Related Security Bulletins