Sploitus

CVE-2024-11042

1 known exploit for CVE-2024-11042

In invoke-ai/invokeai version v5.0.2, the web API `POST /api/v1/images/delete` is vulnerable to Arbitrary File Deletion. This vulnerability allows unauthorized attackers to delete arbitrary files on the server, potentially including critical or sensitive system files such as SSH keys, SQLite databases, and configuration files. This can impact the integrity and availability of applications relying on these files.

Affected products
Invokeai
Fix
Available
CVSS 3.0
9.1 CRITICAL
EPSS
1.5% (72th percentile)
Weakness
CWE-73
NVD status
Deferred
Published
2025-03-20
CVE-2024-11042 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2024-11042

Proof-of-concept code and exploit modules indexed by Sploitus