- Description
- A remote code execution vulnerability exists in invoke-ai/invokeai versions 5.3.1 through 5.4.2 via the /api/v2/models/install API. The vulnerability arises from unsafe deserialization of model files using torch.load without proper validation. Attackers can exploit this by embedding malicious code in model files, which is executed upon loading. This issue is fixed in version 5.4.3.
- Source
- security@huntr.dev
- NVD status
- Deferred
CVSS 3.0
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- security@huntr.dev
- CWE-502
- Hype score
- Not currently trending
#CVE-2024-12029 – #InvokeAI #Deserialization of #Untrusted_Data #vulnerability https://t.co/GNMwZSv6cg https://t.co/zAnZQvtNI9
@omvapt
18 Jul 2025
59 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Deep Dive: CVE-2024-12029 (Critical RCE in InvokeAI) ⚠️ CVSS 9.8 | EPSS 61.17% An unprotected API + unsafe torch deserialization = full system takeover. Attackers can host malicious model files and trigger remote code execution via the /api/v2/models/install endpoint. No au
@offsectraining
17 Jul 2025
3127 Impressions
2 Retweets
22 Likes
8 Bookmarks
0 Replies
0 Quotes
CVE-2024-12029 A remote code execution vulnerability exists in invoke-ai/invokeai versions 5.3.1 through 5.4.2 via the /api/v2/models/install API. The vulnerability arises from unsa… https://t.co/MIHBoqc8mW
@CVEnew
22 Mar 2025
353 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Exploit for InvokeAI, #DL model management tool: RCE #CVE-2024-12029. The backend downloads the file and deserializes it unsafely using #PyTorch's torch.load() : https://t.co/Qb0NvaxTKo
@c3retc3
22 Feb 2025
124 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes