CVE-2026-35050 | oobabooga text-generation-webui up to 4.1.0 Setting download-model.py path traversal (GHSA-jg96-p5p6-q3cv)
A vulnerability was found in oobabooga text-generation-webui up to 4.1.0. It has been classified as critical. Affected by this vulnerability is an unknown functionality of the file download-model.py of the component Setting Handler. The manipulation leads to path traversal.
This vulnerability is traded as CVE-2026-35050. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.