CVE-2026-82288

Source
https://cve.org/CVERecord?id=CVE-2026-82288
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82288.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-82288
Published
2026-08-28T16:19:05.909Z
Modified
2026-08-30T03:48:23.293647841Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Stable Diffusion WebUI Credential Disclosure via /sdapi/v1/cmd-flags
Details

Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags endpoint that returns parsed command-line arguments including gradioauth and apiauth values in cleartext. Unauthenticated attackers can access this endpoint to retrieve configured usernames and passwords, then use them to authenticate to the interface and access the application.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82288.json",
    "cwe_ids": [
        "CWE-522"
    ],
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/automatic1111/stable-diffusion-webui

Affected ranges

Type
GIT
Repo
https://github.com/automatic1111/stable-diffusion-webui
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.10.1"
        },
        {
            "fixed": "1.10.1"
        }
    ]
}

Affected versions

v1.*
v1.0.0-pre
v1.1.0
v1.1.1
v1.10.0
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.3.2
v1.4.0
v1.4.1
v1.5.0-RC
v1.5.1-RC
v1.5.2-RC
v1.6.0-RC
v1.7.0-RC
v1.9.0-RC
v1.9.1
v1.9.2
v1.9.3
v1.9.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82288.json"