PT-2026-83311 · Unknown · Stable-Diffusion-Webui

·

CVE-2026-82288

·

Published

2026-08-28

·

Updated

2026-08-28

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Stable Diffusion WebUI versions prior to 1.10.2
Description An issue exists where the '/sdapi/v1/cmd-flags' endpoint returns parsed command-line arguments in cleartext. This allows unauthenticated attackers to retrieve sensitive credentials, specifically the gradio auth and api auth variables, which can then be used to authenticate to the interface and gain unauthorized access to the application.
Recommendations Update Stable Diffusion WebUI to version 1.10.2 or later. As a temporary mitigation, restrict access to the '/sdapi/v1/cmd-flags' endpoint.

Exploit

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82288

Affected Products

Stable-Diffusion-Webui