PT-2025-12097 · Unknown · Automatic1111/Stable-Diffusion-Webui

Published

2025-03-20

·

Updated

2025-08-05

·

CVE-2024-11045

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions automatic1111/stable-diffusion-webui version 1.10.0
Description A Cross-Site WebSocket Hijacking (CSWSH) vulnerability allows an attacker to clone a malicious server extension from a GitHub repository. The vulnerability is due to a lack of proper validation on WebSocket connections at the /queue/join API endpoint (ws://127.0.0.1:7860/queue/join), enabling unauthorized actions on the server. This can lead to unauthorized cloning of server extensions, execution of malicious scripts, data exfiltration, and potential denial of service (DoS).
Recommendations Ensure proper validation of WebSocket connections at ws://127.0.0.1:7860/queue/join to prevent unauthorized actions.

Exploit

Fix

DoS

Improper Access Control

Origin Validation Error

Weakness Enumeration

Related Identifiers

CVE-2024-11045

Affected Products

Automatic1111/Stable-Diffusion-Webui