CVE-2026-35484 | oobabooga text-generation-webui up to 4.2 API Response load_preset path traversal (GHSA-w3cv-4447-5hf5)
A vulnerability described as critical has been identified in oobabooga text-generation-webui up to 4.2. The impacted element is the function load_preset of the component API Response Handler. Executing a manipulation can lead to path traversal.
This vulnerability is registered as CVE-2026-35484. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.