MEDIUM
invoke-ai
CVE published 2026-07-22
CVE-2026-65012
CVE-2026-65012 is an unauthenticated directory enumeration vulnerability in InvokeAI before 6.13.7. The vulnerability exists in the GET /api/v2/models/scan_folder endpoint, which accepts attacker-controlled scan_path parameters. This allows unauthenticated attackers to recursively enumerate arbitrary server filesystem directories and use HTTP response codes to determine file existence and readability, byp [truncated]