PT-2024-24361 · Kohya Ss · Kohya Ss

Sylwia-Budzynska

·

Published

2024-04-16

·

Updated

2025-09-08

·

CVE-2024-32023

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Kohya ss versions prior to 23.1.5
Description Kohya ss is a GUI for Kohya's Stable Diffusion trainers. It is vulnerable to a path injection in the common gui.py find and replace function.
Recommendations For versions prior to 23.1.5, update to version 23.1.5 to resolve the issue. As a temporary workaround, consider restricting access to the find and replace function in the common gui.py file until the update is applied.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-32023
GHSA-P945-7QM7-7J53

Affected Products

Kohya Ss