InvokeAI before 6.13.7 contains an unauthenticated directory enumeration vulnerability in the GET /api/v2/models/scan_folder endpoint that accepts attacker-controlled scan_path parameters. Unauthenticated attackers can recursively enumerate arbitrary server filesystem directories and use HTTP response codes to determine file existence and readability, bypassing multi-user mode access controls.
References
Configurations
No configuration.
History
22 Jul 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-22 17:16
Updated : 2026-07-23 16:17
NVD link : CVE-2026-65012
Mitre link : CVE-2026-65012
CVE.ORG link : CVE-2026-65012
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
