Kohya_ss Vulnerable to Command Injection in `finetune_gui.py` - Fix in 23.1.5
CVE-2024-32027
9.1CRITICAL
What is CVE-2024-32027?
The Kohya_ss graphical user interface for Kohya's Stable Diffusion trainers is subject to a significant security vulnerability related to command injection. This issue exists in version 22.6.1 and prior, affecting the execution of commands through improperly sanitized inputs in the 'finetune_gui.py' script. The vulnerability allows attackers to exploit the application by injecting arbitrary code, posing risks to system integrity and data security. A patched version, 23.1.5, is available to mitigate this threat, emphasizing the importance for users to update their installations promptly.
Affected Version(s)
kohya_ss >= 22.6.1, < 23.1.5