CVE-2026-35486 | oobabooga text-generation-webui up to 4.2 requests.get server-side request forgery
A vulnerability has been found in oobabooga text-generation-webui up to 4.2 and classified as critical. Affected by this issue is the function requests.get. Performing a manipulation results in server-side request forgery.
This vulnerability is known as CVE-2026-35486. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.