PT-2025-12094 · Invokeai · Invokeai
Published
2025-03-20
·
Updated
2025-03-22
·
CVE-2024-11042
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
invoke-ai/invokeai version v5.0.2
Description
The web API
POST /api/v1/images/delete is vulnerable to Arbitrary File Deletion, allowing unauthorized attackers to delete arbitrary files on the server. This can include critical or sensitive system files such as SSH keys, SQLite databases, and configuration files, potentially impacting the integrity and availability of applications relying on these files.Recommendations
For invoke-ai/invokeai version v5.0.2, consider disabling the
POST /api/v1/images/delete API endpoint until a patch is available to prevent unauthorized file deletion. Restrict access to sensitive system files to minimize the risk of exploitation.Fix
Path traversal
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Invokeai