Skip to content
InvokeAIGHSA-227r-w5j2-6243

InvokeAI Arbitrary File Deletion vulnerability

Critical9.1CVE-2024-11042 · Published Mar 20, 2025 · updated Jun 29, 2026

In invoke-ai/invokeai version v5.0.2, the web API `POST /api/v1/images/delete` is vulnerable to Arbitrary File Deletion. This vulnerability allows unauthorized attackers to delete arbitrary files on the server, potentially including critical or sensitive system files such as SSH keys, SQLite databases, and configuration files. This can impact the integrity and availability of applications relying on these files.

GitHub advisory

Affected versions

PackageAffectedFixed in
invokeai
PyPI
< 5.3.0rc15.3.0rc1
Details and references
CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-20, CWE-22, CWE-73
Also known as
CVE-2024-11042, PYSEC-2026-358

More InvokeAI advisories

All InvokeAI
Advisory
InvokeAI has External Control of File Name or Path
Critical9.8Sep 18, 2025
InvokeAI Deserialization of Untrusted Data vulnerability
Critical9.8Mar 21, 2025
InvokeAI Uncontrolled Resource Consumption vulnerability
High7.5Mar 20, 2025
InvokeAI has Denial of Service (DoS) vulnerability in `/api/v1/images/upload`
High7.5Mar 20, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.