peter bassill · operator
$ cve CVE-2024-12029 JSON

CVE-2024-12029

9.8
CRITICAL · CVSS 3.0 · EPSS 6% (pctl 93)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A remote code execution vulnerability exists in invoke-ai/invokeai versions 5.3.1 through 5.4.2 via the /api/v2/models/install API. The vulnerability arises from unsafe deserialization of model files using torch.load without proper validation. Attackers can exploit this by embedding malicious code in model files, which is executed upon loading. This issue is fixed in version 5.4.3.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS5.98% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2025-03-20
Last modified2026-06-17

References

→ the Explorer  ·  watch your stack  ·  NVD