Skip to content
InvokeAIGHSA-mcrp-whpw-jp68

InvokeAI Deserialization of Untrusted Data vulnerability

Critical9.8CVE-2024-12029 · Published Mar 21, 2025 · updated May 20, 2025

A remote code execution vulnerability exists in invoke-ai/invokeai versions 5.3.1 through 5.4.2 via the /api/v2/models/install API. The vulnerability arises from unsafe deserialization of model files using torch.load without proper validation. Attackers can exploit this by embedding malicious code in model files, which is executed upon loading. This issue is fixed in version 5.4.3rc2.

GitHub advisory

Affected versions

PackageAffectedFixed in
invokeai
PyPI
>= 5.3.1, < 5.4.3rc25.4.3rc2
Details and references

More InvokeAI advisories

All InvokeAI
Advisory
InvokeAI has External Control of File Name or Path
Critical9.8Sep 18, 2025
InvokeAI Arbitrary File Deletion vulnerability
Critical9.1Mar 20, 2025
InvokeAI Uncontrolled Resource Consumption vulnerability
High7.5Mar 20, 2025
InvokeAI has Denial of Service (DoS) vulnerability in `/api/v1/images/upload`
High7.5Mar 20, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.