# CVE-2025-12487

## Summary

- **CVE ID:** CVE-2025-12487
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-807
- **Published:** Nov 6, 2025
- **Last Modified:** Mar 13, 2026

## Description

oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of oobabooga text-generation-webui. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the handling of the trust_remote_code parameter provided to the join endpoint. The issue results from the lack of proper validation of a user-supplied argument before using it to load a model. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-26681.

## Affected Products

- oobabooga — text-generation-webui (2.5)

## References

- [CNA](https://www.zerodayinitiative.com/advisories/ZDI-25-982/)
- [CNA](https://github.com/oobabooga/text-generation-webui/commit/b5a6904c4ac4049823396090360b6f566f4e4603)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.85%
- **EPSS Percentile:** 55.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._