CVE-2026-82288 UNKNOWN

CVE-2026-82288

Published: 2026-08-28

Description

Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags endpoint that returns parsed command-line arguments including gradio_auth and api_auth values in cleartext. Unauthenticated attackers can access this endpoint to retrieve configured usernames and passwords, then use them to authenticate to the interface and access the application.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…