漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Path Traversal and Arbitrary File Deletion in invoke-ai/invokeai
Vulnerability Description
A vulnerability in invokeai version v6.0.0a1 and below allows attackers to perform path traversal and arbitrary file deletion via the GET /api/v1/images/download/{bulk_download_item_name} endpoint. By manipulating the filename arguments, attackers can read and delete any files on the server, including critical system files such as SSH keys, databases, and configuration files. This vulnerability results in high confidentiality, integrity, and availability impacts.
CVSS Information
N/A
Vulnerability Type
文件名或路径的外部可控制
Vulnerability Title
Invoke 安全漏洞
Vulnerability Description
Invoke是InvokeAI开源的一个稳定扩散模型的领先创意引擎。 Invoke v6.0.0a1及之前版本存在安全漏洞,该漏洞源于GET /api/v1/images/download/{bulk_download_item_name}端点未正确处理文件名参数,可能导致路径遍历和任意文件删除攻击。
CVSS Information
N/A
Vulnerability Type
N/A