Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Remote Code Execution via Model Deserialization in invoke-ai/invokeai
Vulnerability Description
A remote code execution vulnerability exists in invoke-ai/invokeai versions 5.3.1 through 5.4.2 via the /api/v2/models/install API. The vulnerability arises from unsafe deserialization of model files using torch.load without proper validation. Attackers can exploit this by embedding malicious code in model files, which is executed upon loading. This issue is fixed in version 5.4.3.
CVSS Information
N/A
Vulnerability Type
可信数据的反序列化
Vulnerability Title
Invoke 安全漏洞
Vulnerability Description
Invoke是InvokeAI开源的一个稳定扩散模型的领先创意引擎。 Invoke 5.3.1至5.4.2版本存在安全漏洞,该漏洞源于模型文件反序列化不当,可能导致远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A