Kohyass is a GUI for Kohya's Stable Diffusion trainers. Kohyass is vulnerable to a path injection in the common_gui.py find_and_replace function. This vulnerability is fixed in 23.1.5.
common_gui.py
find_and_replace