Improper access control in Text Generation Web UI - #VU127420
Published: April 24, 2026
Text Generation Web UI
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in file path validation logic when handling file or directory path requests. A remote attacker can alter the letter case of a blocked file or directory path to disclose sensitive information.
Exploitation is limited to case-insensitive file systems such as those used by Windows and macOS, and does not affect Linux.