Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-35487 is a path traversal vulnerability in versions of oobabooga text-generation-webui prior to 4.3. It allows unauthenticated attackers to read arbitrary . txt files on the server by exploiting the load_prompt() function. The file contents are returned directly in the API response. This vulnerability has a medium severity rating and is fixed in version 4.3. Join the discussion | CVE Database V5 | 04/07/2026, 14:50:25 UTC Added: 04/07/2026, 15:31:13 UTC |
0 text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, he superbooga and superboogav2 RAG extensions fetch user-supplied URLs via requests.get() with zero validation — no scheme check, no IP filtering, no hostname allowlist. An attacker can access cloud metadata endpoints, steal IAM credentials, and probe internal services. The fetched content is exfiltrated through the RAG pipeline. This vulnerability is fixed in 4.3. Join the discussion | CVE Database V5 | 04/07/2026, 14:49:37 UTC Added: 04/07/2026, 15:31:13 UTC |
CVE-2026-35485 is a path traversal vulnerability in oobabooga's text-generation-webui versions prior to 4.3. It allows unauthenticated attackers to read arbitrary files on the server by sending crafted directory traversal payloads via the API. The vulnerability arises because the load_grammar() function does not properly restrict pathname access, and Gradio does not validate dropdown input server-side. This issue is fixed in version 4.3. The vulnerability has a high severity score of 7.5 and impacts confidentiality but not integrity or availability. Join the discussion | CVE Database V5 | 04/07/2026, 14:47:37 UTC Added: 04/07/2026, 15:01:18 UTC |
text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticated path traversal vulnerability in load_preset() allows reading any .yaml file on the server filesystem. The parsed YAML key-value pairs (including passwords, API keys, connection strings) are returned in the API response. This vulnerability is fixed in 4.3. Join the discussion | CVE Database V5 | 04/07/2026, 14:46:42 UTC Added: 04/07/2026, 15:01:18 UTC |
CVE-2026-35483 is a path traversal vulnerability in the oobabooga text-generation-webui prior to version 4.3. It allows unauthenticated attackers to read files with . jinja, . jinja2, . yaml, or . yml extensions from anywhere on the server filesystem. The vulnerability specifically exposes . jinja files verbatim and extracts parsed keys from . yaml files. Join the discussion | CVE Database V5 | 04/07/2026, 14:45:07 UTC Added: 04/07/2026, 15:01:18 UTC |
CVE-2026-35050 is a critical path traversal vulnerability in oobabooga's text-generation-webui versions prior to 4.1.1. It allows users to save extension settings as Python files in the application root directory, potentially overwriting existing Python files such as download-model.py. This overwritten file can then be executed via the Model menu to download a new model, enabling arbitrary code execution. The vulnerability is fixed in version 4.1.1. Join the discussion | CVE Database V5 | 04/06/2026, 17:30:20 UTC Added: 04/06/2026, 18:00:30 UTC |
0 oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of oobabooga text-generation-webui. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the trust_remote_code parameter provided to the join endpoint. The issue results from the lack of proper validation of a user-supplied argument before using it to load a model. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-26681. Join the discussion | CVE Database V5 | 11/06/2025, 20:12:07 UTC Added: 11/06/2025, 20:35:54 UTC |
0 oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of oobabooga text-generation-webui. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the trust_remote_code parameter provided to the load endpoint. The issue results from the lack of proper validation of a user-supplied argument before using it to load a model. An attacker can leverage this vulnerability to execute code in the context of the service account. . Was ZDI-CAN-26680. Join the discussion | CVE Database V5 | 11/06/2025, 20:11:52 UTC Added: 11/06/2025, 20:35:54 UTC |
Showing 1 to 8 of 8 results