Arbitrary File Deletion Vulnerability in InvokeAI by Invoke AI
CVE-2024-11042

9.1CRITICAL

Key Information:

Vendor

Invoke-ai

Vendor
CVE Published:
20 March 2025

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2024-11042?

The InvokeAI product version v5.0.2 is vulnerable to a security flaw within its web API endpoint, specifically the POST /api/v1/images/delete. This vulnerability permits unauthorized users to delete arbitrary files on the server, which could include critical data like SSH keys, SQLite databases, and essential configuration files. Such unauthorized deletion jeopardizes the integrity and availability of applications that depend on these files, posing significant risks to data security and operational continuity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

invoke-ai/invokeai < 5.3.0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V3.0

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.