PatchSiren

invoke-ai CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM invoke-ai CVE published 2026-07-22

CVE-2026-65012

CVE-2026-65012 is an unauthenticated directory enumeration vulnerability in InvokeAI before 6.13.7. The vulnerability exists in the GET /api/v2/models/scan_folder endpoint, which accepts attacker-controlled scan_path parameters. This allows unauthenticated attackers to recursively enumerate arbitrary server filesystem directories and use HTTP response codes to determine file existence and readability, byp [truncated]