Invoke是InvokeAI开源的一个稳定扩散模型的领先创意引擎。 Invoke v5.0.2版本存在输入验证错误漏洞,该漏洞源于POST /api/v1/images/delete API中的任意文件删除漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| invoke-ai | invoke-ai/invokeai | unspecified ~ 5.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Proof-of-concept for In invoke-ai/invokeai version v5.0.2 Arbitrary File Deletion. | https://github.com/gothburz/CVE-2024-11042 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2024-12029 | Remote Code Execution via Model Deserialization in invoke-ai/invokeai | |
| CVE-2024-11043 | Denial of Service (DoS) via Large Payload in Board Name Field in invoke-ai/invokeai | |
| CVE-2024-10821 | Denial of Service (DoS) in invoke-ai/invokeai |
No comments yet