Input validation error in Text Generation Web UI - #VU127430

 

Input validation error in Text Generation Web UI - #VU127430

Published: April 24, 2026


Vulnerability identifier: #VU127430
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper input validation in the API extension when handling requests to the /v1/internal/model/load endpoint. A remote attacker can send a specially crafted request with a trust_remote_code argument to execute arbitrary code.

By default, authentication is not required to exploit this vulnerability.


Affected software

Text Generation Web UI

Remediation

Install security update from vendor's website.

Text Generation Web UI - update to 4.0

External References

Related Security Bulletins