CVE-2024-11042
CVSS 3.0 Score 9.1 of 10 (critical)
Details
Published Mar 20, 2025
CWE ID 20
Summary
CVE-2024-11042: A vulnerability affecting version 5.0.2 of invoke-ai's web API exposes an Arbitrary File Deletion vulnerability through the `POST /api/v1/images/delete` endpoint. Unauthorized attackers can exploit this issue to delete critical or sensitive system files, such as SSH keys, SQLite databases, and configuration files. This vulnerability poses a significant risk to the integrity and availability of applications that rely on these files.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Invoke AI