Invoke AI Remote Code Execution Vulnerability via Unsafe Model File Deserialization
Vulnerability
A remote code execution vulnerability has been identified in Invoke AI versions 5.3.1 prior to 5.4.2. The issue arises in the /api/v2/models/install API, where model files are deserialized using torch.load without adequate validation. This flaw allows attackers to embed malicious code in model files, which is executed when the files are loaded. The vulnerability has been addressed in version 5.4.3.
Impact
Exploitation of this vulnerability allows for remote code execution on the server where Invoke AI is running.
Remediation
Users can upgrade to Invoke AI version 5.4.3 or later to address this vulnerability.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
10.0exploitability
8.1remediation
7.7relevance
0.0threat
4.1urgency
2.9incentive
5.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
