Server-Side Request Forgery (SSRF) in Text Generation Web UI - CVE-2026-35486
Published: April 24, 2026
Text Generation Web UI
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to server-side request forgery in the superbooga and superboogav2 URL fetching functionality when processing user-supplied URLs. A remote attacker can submit a crafted URL to disclose sensitive information.
The fetched content is stored in the RAG pipeline and can become visible in subsequent LLM responses.