CVE-2026-35487 | oobabooga text-generation-webui up to 4.2 API Response load_prompt path traversal
A vulnerability, which was classified as critical, was found in oobabooga text-generation-webui up to 4.2. Affected by this vulnerability is the function load_prompt of the component API Response Handler. Such manipulation leads to path traversal.
This vulnerability is traded as CVE-2026-35487. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.