Server-Side Request Forgery (SSRF) in Text Generation Web UI - CVE-2026-35486

 

Server-Side Request Forgery (SSRF) in Text Generation Web UI - CVE-2026-35486

Published: April 24, 2026


Vulnerability identifier: #VU127423
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-35486
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to server-side request forgery in the superbooga and superboogav2 URL fetching functionality when processing user-supplied URLs. A remote attacker can submit a crafted URL to disclose sensitive information.

The fetched content is stored in the RAG pipeline and can become visible in subsequent LLM responses.


Affected software

Text Generation Web UI

How to mitigate CVE-2026-35486

Install security update from vendor's website.

Text Generation Web UI - update to 4.3

External References

Related Security Bulletins