CVE-2024-32027 is a critical command injection vulnerability affecting Kohya_ss, a GUI for Stable Diffusion trainers, specifically version 22.6.1 in the finetune_gui.py component. This flaw allows unauthenticated attackers to execute arbitrary commands remotely with high impact on confidentiality, integrity, and availability, as indicated by its CVSS score of 9.8. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the high FAUCET Risk Score of 82/100 suggests significant potential for future exploitation. The vulnerability is patched in Kohya_ss version 23.1.5.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 22.6.1, < 24.0.1CPE matchmatch criteria | cpe:2.3:a:bmaltais:kohya_ss:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.