---
id: CVE-2025-62364
title: >-
  text-generation-webui is an open-source web interface for running Large
  Language Models
summary: >-
  text-generation-webui is an open-source web interface for running Large
  Language Models. In versions through 3.13, a Local File Inclusion
  vulnerability exists in the character picture upload feature. An attacker can
  upload a text file co…
severity: medium
cvss: 6.2
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-59
published: '2025-10-13'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T12:10:00.217'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-62364'
references:
  - url: >-
      https://github.com/oobabooga/text-generation-webui/commit/282aa1918907fceec7f903d3dc2bc8492ce8e885
    label: security-advisories@github.com
  - url: >-
      https://github.com/oobabooga/text-generation-webui/security/advisories/GHSA-66rw-q8w5-c2hg
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.0057
epssPercentile: 0.4539
ingestedAt: '2026-10-08T12:39:48.707Z'
---

## Overview

text-generation-webui is an open-source web interface for running Large Language Models. In versions through 3.13, a Local File Inclusion vulnerability exists in the character picture upload feature. An attacker can upload a text file containing a symbolic link to an arbitrary file path. When the application processes the upload, it follows the symbolic link and serves the contents of the targeted file through the web interface. This allows an unauthenticated attacker to read sensitive files on the server, potentially exposing system configurations, credentials, and other confidential information. This vulnerability is fixed in 3.14. No known workarounds exist.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
