PT-2024-24362 · Kohya Ss · Kohya Ss

Sylwia-Budzynska

·

Published

2024-04-16

·

Updated

2025-09-08

·

CVE-2024-32024

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Kohya ss versions prior to 23.1.5
Description Kohya ss is a GUI for Kohya's Stable Diffusion trainers. It is vulnerable to a path injection in the common gui.py add pre postfix function.
Recommendations For versions prior to 23.1.5, update to version 23.1.5 to resolve the issue. As a temporary workaround, consider restricting access to the add pre postfix function in the common gui.py file until the update is applied.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-32024
GHSA-H9FP-J58H-WWRC

Affected Products

Kohya Ss