{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-18T01:01:55.556","vulnerabilities":[{"cve":{"id":"CVE-2024-11042","sourceIdentifier":"security@huntr.dev","published":"2025-03-20T10:15:23.537","lastModified":"2026-04-15T00:35:42.020","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"In invoke-ai/invokeai version v5.0.2, the web API `POST /api/v1/images/delete` is vulnerable to Arbitrary File Deletion. This vulnerability allows unauthorized attackers to delete arbitrary files on the server, potentially including critical or sensitive system files such as SSH keys, SQLite databases, and configuration files. This can impact the integrity and availability of applications relying on these files."},{"lang":"es","value":"En la versión v5.0.2 de evolve-ai/invokeai, la API web `POST /api/v1/images/delete` es vulnerable a la eliminación arbitraria de archivos. Esta vulnerabilidad permite a atacantes no autorizados eliminar archivos arbitrarios del servidor, incluyendo potencialmente archivos críticos o sensibles del sistema, como claves SSH, bases de datos SQLite y archivos de configuración. Esto puede afectar la integridad y la disponibilidad de las aplicaciones que dependen de estos archivos."}],"metrics":{"cvssMetricV30":[{"source":"security@huntr.dev","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.2}]},"weaknesses":[{"source":"security@huntr.dev","type":"Secondary","description":[{"lang":"en","value":"CWE-73"}]}],"references":[{"url":"https://github.com/invoke-ai/invokeai/commit/5440c037674882b2ab7acd59087e9bb04b49657a","source":"security@huntr.dev"},{"url":"https://huntr.com/bounties/635535a7-c804-4789-ac3a-48d951263987","source":"security@huntr.dev"}]}}]}