Remote Code Execution via Model Deserialization in invoke-ai/invokeai
63Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 9.8epss 5.7%
from disclosure to weapon391 days
Published on NVDMar 20
1st PoC+391d
metasploitFeb 7
exploitation probability
5.7%top 8% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A remote code execution vulnerability exists in invoke-ai/invokeai versions 5.3.1 through 5.4.2 via the /api/v2/models/install API. The vulnerability arises from unsafe deserialization of model files using torch.load without proper validation. Attackers can exploit this by embedding malicious code in model files, which is executed upon loading. This issue is fixed in version 5.4.3.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
invoke-ai · invoke-ai/invokeaipublic PoCs found — 1
githubgithub.com/Lu3ky13/Alternative-Approach-Reverse-Shell-Callback-Test-InvokeAI-RCE★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.