PT-2026-63437 · Invokeai+1 · Invokeai

·

CVE-2026-65012

·

Published

2026-07-22

·

Updated

2026-07-22

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions InvokeAI versions prior to 6.13.7
Description An unauthenticated directory enumeration issue exists in the 'GET /api/v2/models/scan folder' endpoint. The endpoint accepts a scan path parameter that can be controlled by an attacker, allowing them to recursively enumerate arbitrary directories on the server filesystem. By analyzing HTTP response codes, an attacker can determine if files exist and are readable, which bypasses access controls implemented for multi-user mode.
Recommendations Update to version 6.13.7 or later. As a temporary mitigation, restrict access to the 'GET /api/v2/models/scan folder' endpoint or avoid using the scan path parameter until the update is applied.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65012

Affected Products

Invokeai