Improper Handling of Case Sensitivity in Text Generation Web UI - #VU127426
Published: April 24, 2026
Text Generation Web UI
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in file path validation logic when handling file or directory paths. A remote attacker can alter the letter case of a blocked file or directory path to disclose sensitive information.
Only case-insensitive file systems, such as those commonly used by Windows and macOS, are affected; Linux is not affected.