CVE-2024-12029

A remote code execution vulnerability exists in invoke-ai/invokeai versions 5.3.1 through 5.4.2 via the /api/v2/models/install API. The vulnerability arises from unsafe deserialization of model files using torch.load without proper validation. Attackers can exploit this by embedding malicious code in model files, which is executed upon loading. This issue is fixed in version 5.4.3.
Configurations

No configuration.

History

20 Mar 2025, 15:15

Type Values Removed Values Added
References () https://huntr.com/bounties/9b790f94-1b1b-4071-bc27-78445d1a87a3 - () https://huntr.com/bounties/9b790f94-1b1b-4071-bc27-78445d1a87a3 -

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-03-20 15:15


NVD link : CVE-2024-12029

Mitre link : CVE-2024-12029

CVE.ORG link : CVE-2024-12029


JSON object : View

Products Affected

No product.

CWE
CWE-502

Deserialization of Untrusted Data