CVE-2026-82288: AUTOMATIC1111 Stable-Diffusion-Webui
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags endpoint that returns parsed command-line arguments including gradio_auth and api_auth values in cleartext. Unauthenticated attackers can access this endpoint to retrieve configured usernames and passwords, then use them to authenticate to the interface and access the application.
Affected products
- AUTOMATIC1111 Stable-Diffusion-Webui: up to and including 1.10.1
Published 2026-08-28. Last modified 2026-09-24.