Path traversal in Text Generation Web UI - CVE-2026-35485
Published: April 24, 2026
Text Generation Web UI
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to path traversal in load_grammar() in modules/ui_parameters.py when handling crafted requests to the /gradio_api/call/load_grammar endpoint. A remote attacker can send a specially crafted request with directory traversal sequences to disclose sensitive information.
Because the submitted dropdown value is not server-side validated and no file extension is appended, any file readable by the server process may be returned.