PT-2025-12094 · Invokeai · Invokeai

Published

2025-03-20

·

Updated

2025-03-22

·

CVE-2024-11042

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions invoke-ai/invokeai version v5.0.2
Description The web API POST /api/v1/images/delete is vulnerable to Arbitrary File Deletion, allowing unauthorized attackers to delete arbitrary files on the server. This can include critical or sensitive system files such as SSH keys, SQLite databases, and configuration files, potentially impacting the integrity and availability of applications relying on these files.
Recommendations For invoke-ai/invokeai version v5.0.2, consider disabling the POST /api/v1/images/delete API endpoint until a patch is available to prevent unauthorized file deletion. Restrict access to sensitive system files to minimize the risk of exploitation.

Fix

Path traversal

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-11042
GHSA-227R-W5J2-6243

Affected Products

Invokeai