PT-2025-12095 · Invokeai · Invokeai

Publicado

2025-03-20

·

Atualizado

2025-03-20

·

CVE-2024-11043

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions invoke-ai/invokeai version v5.0.2
Description A Denial of Service (DoS) issue was discovered in the "/api/v1/boards/{board id}" endpoint. This occurs when an excessively large payload is sent in the board name field during a PATCH request, causing the UI to become unresponsive and making it impossible for users to interact with or manage the affected board. The option to delete the board also becomes inaccessible.
Recommendations For invoke-ai/invokeai version v5.0.2, consider restricting access to the "/api/v1/boards/{board id}" endpoint to prevent exploitation until a fix is available. As a temporary workaround, limit the size of the payload that can be sent in the board name field to prevent the UI from becoming unresponsive.

Exploit

Correção

DoS

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2024-11043
GHSA-FFH5-W482-C7M5

Produtos afetados

Invokeai