Arbitrary File Deletion Vulnerability in InvokeAI by Invoke AI
CVE-2024-11042
Key Information:
- Vendor
Invoke-ai
- Status
- Vendor
- CVE Published:
- 20 March 2025
Badges
What is CVE-2024-11042?
The InvokeAI product version v5.0.2 is vulnerable to a security flaw within its web API endpoint, specifically the POST /api/v1/images/delete. This vulnerability permits unauthorized users to delete arbitrary files on the server, which could include critical data like SSH keys, SQLite databases, and essential configuration files. Such unauthorized deletion jeopardizes the integrity and availability of applications that depend on these files, posing significant risks to data security and operational continuity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
invoke-ai/invokeai < 5.3.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.0
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
