Relative Path Traversal in Text Generation Web UI - CVE-2025-62364
Published: April 24, 2026
Text Generation Web UI
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper neutralization of file paths in the character picture upload feature when processing an uploaded symbolic link file. A remote attacker can upload a crafted .txt file containing a symbolic link and access the uploaded file URL to disclose sensitive information.
The issue can expose server files such as system configuration files and credentials.