Junglewise Threat Intelligence

CVE-2024-11042: PYSEC-2026-358 - InvokeAI Arbitrary File Deletion vulnerability

CVE-2024-11042 · Severity: low · CVSS 3 · Published 2026-06-29

Technologies: invokeai (PyPI). Vendors: PyPI.

Executive brief

InvokeAI is an AI image generation and editing application with a web-based API. An unauthenticated attacker can delete arbitrary files on the server through a directory traversal vulnerability in the image deletion endpoint, potentially destroying critical system files, configuration data, and SSH keys, which could lead to complete loss of service and compromise of system security.

Technical details

The vulnerability exists in the POST /api/v1/images/delete endpoint in InvokeAI versions prior to 5.3.0rc1, which fails to properly validate file paths before deletion. An attacker can use directory traversal sequences (../) to escape the intended image directory and delete arbitrary files on the system, including SSH keys, SQLite databases, and configuration files. No authentication is required and the attack is triggered over the network with a simple HTTP request. The vulnerability impacts both the confidentiality of stored data and availability of the application. A patch was released in version 5.3.0rc1 and backported to version 5.2.0.

Affected products

  • InvokeAI InvokeAI all versions before 5.3.0rc1

Timeline

  • 2025-03-20: disclosed
  • 2025-03-20: patched: Fixed in version 5.3.0rc1

References

Related threats