Логотип exploitDog
bind:CVE-2024-12029
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-12029

Количество 2

Количество 2

nvd логотип

CVE-2024-12029

11 месяцев назад

A remote code execution vulnerability exists in invoke-ai/invokeai versions 5.3.1 through 5.4.2 via the /api/v2/models/install API. The vulnerability arises from unsafe deserialization of model files using torch.load without proper validation. Attackers can exploit this by embedding malicious code in model files, which is executed upon loading. This issue is fixed in version 5.4.3.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-mcrp-whpw-jp68

11 месяцев назад

InvokeAI Deserialization of Untrusted Data vulnerability

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-12029

A remote code execution vulnerability exists in invoke-ai/invokeai versions 5.3.1 through 5.4.2 via the /api/v2/models/install API. The vulnerability arises from unsafe deserialization of model files using torch.load without proper validation. Attackers can exploit this by embedding malicious code in model files, which is executed upon loading. This issue is fixed in version 5.4.3.

CVSS3: 9.8
49%
Средний
11 месяцев назад
github логотип
GHSA-mcrp-whpw-jp68

InvokeAI Deserialization of Untrusted Data vulnerability

CVSS3: 9.8
49%
Средний
11 месяцев назад

Уязвимостей на страницу