CVE-2026-65012

InvokeAI before 6.13.7 contains an unauthenticated directory enumeration vulnerability in the GET /api/v2/models/scan_folder endpoint that accepts attacker-controlled scan_path parameters. Unauthenticated attackers can recursively enumerate arbitrary server filesystem directories and use HTTP response codes to determine file existence and readability, bypassing multi-user mode access controls.
Configurations

No configuration.

History

22 Jul 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-22 17:16

Updated : 2026-07-23 16:17


NVD link : CVE-2026-65012

Mitre link : CVE-2026-65012

CVE.ORG link : CVE-2026-65012


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function