
CVE-2026-35485 text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticated path traversal vulnerability in load_grammar… https://www.cve.org/CVERecord?id=CVE-2026-35485
Post summary
The post informs that text-generation-webui prior to 4.3 contains an unauthenticated path traversal flaw in its load_grammar function, with no PoC, exploit, patch or active exploitation information given.
