What is CVE-2026-65012?
This is an unauthenticated directory enumeration vulnerability in InvokeAI versions prior to 6.13.7, allowing attackers to recursively list server filesystem directories through the GET /api/v2/models/scan_folder endpoint by controlling the scan_path parameter. Affected systems risk exposure of sensitive file structures, requiring an immediate update to version 6.13.7 or later.
Azərbaycanca: Bu zəiflik InvokeAI platformasının 6.13.7-dən əvvəlki versiyalarında aşkarlanıb və autentifikasiya olunmamış istifadəçilərə `GET /api/v2/models/scan_folder` endpoint-i vasitəsilə server fayl sistemindəki qovluqları icazəsiz oxumağa imkan verir. Təsirə məruz qalan sistemlərdə hücumçular `scan_path` parametrini manipulyasiya edərək həssas məlumatları ələ keçirə bilər. Dərhal 6.13.7 və ya daha yuxarı versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
What is the CVE-2026-65012 vulnerability found in InvokeAI and which versions are affected?
CVE-2026-65012 is an unauthenticated directory enumeration vulnerability in InvokeAI versions prior to 6.13.7, allowing attackers to list server filesystem directories through the `GET /api/v2/models/scan_folder` endpoint.
How to protect against CVE-2026-65012 vulnerability?
To protect against this vulnerability, it is recommended to immediately update InvokeAI to version 6.13.7 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.