CVE-2025-12487CRITICAL 9.8EPSS p50.7%

CVE-2025-12487CVE-2025-12487

Description

oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of oobabooga text-generation-webui. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the trust_remote_code parameter provided to the join endpoint. The issue results from the lack of proper validation of a user-supplied argument before using it to load a model. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-26681.

Scoring

CVSS 3.09.8 (CRITICAL)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.77% probability of exploitation · percentile 50.7% · 2026-06-19T12:03:05Z
Published2025-11-06
Last modified2026-04-15

Underlying weaknesses· 1

CWE-807

References

  1. https://github.com/oobabooga/text-generation-webui/commit/b5a6904c4ac4049823396090360b6f566f4e4603
  2. https://www.zerodayinitiative.com/advisories/ZDI-25-982/

1

TypeTargetConfidenceTier
WeaknessReliance on Untrusted Inputs in a Security Decisioncwe-8070%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-12488
CVE
CVE-2026-0766
CVE
CVE-2025-64496
CVE
CVE-2026-0765
CVE
CVE-2026-0764
CVE
CVE-2025-63389
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.