CVE 6.2 MEDIUM

text-generation-webui allows arbitrary file read via symbolic link upload_CVE-2025-62364

6.2 / 10
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

text-generation-webui is an open-source web interface for running Large Language Models. In versions through 3.13, a Local File Inclusion vulnerability exists in the character picture upload feature. An attacker can upload a text file containing a symbolic link to an arbitrary file path. When the application processes the upload, it follows the symbolic link and serves the contents of the targeted file through the web interface. This allows an unauthenticated attacker to read sensitive files on the server, potentially exposing system configurations, credentials, and other confidential information. This vulnerability is fixed in 3.14. No known workarounds exist.

Basic Information

ID CVE-2025-62364
Source GitHub_M
Published Oct 13, 2025 at 20:30

Affected Product

Vendor oobabooga
Product text-generation-webui
Version <= 3.13
Affected Versions oobabooga text-generation-webui <= 3.13

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.