CVE-2024-12029

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-12029
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-12029.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-12029
Aliases
Published
2025-03-20T10:15:26Z
Modified
2025-03-21T15:42:26.728575Z
Summary
[none]
Details

A remote code execution vulnerability exists in invoke-ai/invokeai versions 5.3.1 through 5.4.2 via the /api/v2/models/install API. The vulnerability arises from unsafe deserialization of model files using torch.load without proper validation. Attackers can exploit this by embedding malicious code in model files, which is executed upon loading. This issue is fixed in version 5.4.3.

References

Affected packages

Git / github.com/invoke-ai/invokeai

Affected ranges

Type
GIT
Repo
https://github.com/invoke-ai/invokeai
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed