CVE-2024-11042

CVSS 3.0 Score 9.1 of 10 (critical)

Details

Published Mar 20, 2025
CWE ID 20

Summary

CVE-2024-11042: A vulnerability affecting version 5.0.2 of invoke-ai's web API exposes an Arbitrary File Deletion vulnerability through the `POST /api/v1/images/delete` endpoint. Unauthorized attackers can exploit this issue to delete critical or sensitive system files, such as SSH keys, SQLite databases, and configuration files. This vulnerability poses a significant risk to the integrity and availability of applications that rely on these files.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share