Input validation error in Text Generation Web UI - #VU127419

 

Input validation error in Text Generation Web UI - #VU127419

Published: April 24, 2026


Vulnerability identifier: #VU127419
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper input validation in the API extension when handling a crafted API request to the "/v1/internal/model/load" endpoint. A remote attacker can supply a crafted "args" value that sets "trust_remote_code" to true to execute arbitrary code.

By default, authentication is not required to exploit this vulnerability.


Affected software

Text Generation Web UI

Remediation

Install security update from vendor's website.

Text Generation Web UI - update to 4.0

External References

Related Security Bulletins