Skip to content
InvokeAIGHSA-ffh5-w482-c7m5

InvokeAI Uncontrolled Resource Consumption vulnerability

High7.5CVE-2024-11043 · Published Mar 20, 2025 · updated Jul 7, 2026

A Denial of Service (DoS) vulnerability was discovered in the /api/v1/boards/{board_id} endpoint of invoke-ai/invokeai version v5.0.2. This vulnerability occurs when an excessively large payload is sent in the board_name field during a PATCH request. By sending a large payload, the UI becomes unresponsive, rendering it impossible for users to interact with or manage the affected board. Additionally, the option to delete the board becomes inaccessible, amplifying the severity of the issue.

GitHub advisory

Affected versions

PackageAffectedFixed in
invokeai
PyPI
<= 5.0.2No fix yet
Details and references

More InvokeAI advisories

All InvokeAI
Advisory
InvokeAI has External Control of File Name or Path
Critical9.8Sep 18, 2025
InvokeAI Deserialization of Untrusted Data vulnerability
Critical9.8Mar 21, 2025
InvokeAI Arbitrary File Deletion vulnerability
Critical9.1Mar 20, 2025
InvokeAI has Denial of Service (DoS) vulnerability in `/api/v1/images/upload`
High7.5Mar 20, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.