Improper access control in Text Generation Web UI - #VU127420

 

Improper access control in Text Generation Web UI - #VU127420

Published: April 24, 2026


Vulnerability identifier: #VU127420
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in file path validation logic when handling file or directory path requests. A remote attacker can alter the letter case of a blocked file or directory path to disclose sensitive information.

Exploitation is limited to case-insensitive file systems such as those used by Windows and macOS, and does not affect Linux.


Affected software

Text Generation Web UI

Remediation

Install security update from vendor's website.

Text Generation Web UI - update to 4.3

External References

Related Security Bulletins