CVE-2026-35485 | oobabooga text-generation-webui up to 4.2 load_grammar path traversal (GHSA-hqg5-487v-5mc6)
A vulnerability classified as critical has been found in oobabooga text-generation-webui up to 4.2. This affects the function load_grammar. The manipulation leads to path traversal.
This vulnerability is documented as CVE-2026-35485. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.