Executive brief
Infinite Image Browsing is a file management and image organization application that can be deployed as a standalone app or as an extension to Stable Diffusion WebUI. A flaw in its access control logic allows attackers to read files outside permitted directories by requesting paths that start with an allowed directory name. For example, if /data/images is allowed, an attacker can read /data/images_private/secret.txt. This bypasses the confinement controls in network-exposed deployments, risking exposure of sensitive image metadata, generated outputs, or configuration files.
Technical details
The vulnerability is a path traversal bypass in scripts/iib/api.py. The is_path_trusted function uses path.startswith(parent_path) to validate that a requested file lies within an allowed parent directory, but fails to append a path separator (os.sep) to parent_path before comparison. This permits directory names that begin with an allowed path to bypass the check—for example, /data/images_private/ will pass validation when /data/images/ is whitelisted. Access control activation depends on get_enable_access_control in scripts/iib/tool.py, which is enabled by default in network-exposed deployments (those started with share, ngrok, listen, or server_name flags) but disabled in standalone mode. An unauthenticated remote attacker can exploit this by sending a crafted file request to the FileResponse endpoint. The fix involves comparing against parent_path + os.sep instead of parent_path alone.
Affected products
- zanllp Infinite Image Browsing <1.8.1
Timeline
- 2026-08-21: disclosed