CVE-2025-6237 is a critical path traversal and arbitrary file deletion vulnerability affecting InvokeAI version v6.0.0a1 and earlier. Attackers can exploit the GET /api/v1/images/download/{bulk_download_item_name} endpoint to read and delete any files on the server, including sensitive system files. This unauthenticated vulnerability carries a CVSS score of 9.8 (CRITICAL), indicating high impacts to confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code, the vulnerability has garnered community discussion, suggesting awareness among threat actors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Invoke-Ai | Invoke-Ai/Invokeai | >= unspecified, <= latestCNA affected |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.