Automatic1111 maintains a single, widely deployed web interface for the Stable Diffusion image-generation model that has become a standard tool for researchers and practitioners working with generative AI. Vulnerabilities affecting this product skew toward serious outcomes and frequently acquire public exploit code, clustering around input-validation and access-control weaknesses characteristic of web-facing interfaces—including path traversal, cross-site scripting, resource exhaustion, and improper origin validation. Defenders should treat updates to this interface as a priority, particularly where instances are exposed to untrusted networks; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Automatic1111 over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-11045CRITICAL A Cross-Site WebSocket Hijacking (CSWSH) vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows an attacker to clone a malicious server extension from a GitHub | Mar 20, 2025 | 9.6 | 26 | NO | NO |
CVE-2024-11044MEDIUM An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a special | Mar 20, 2025 | 6.1 | 24 | NO | YES |
CVE-2024-10935HIGH automatic1111/stable-diffusion-webui version 1.10.0 contains a vulnerability where the server fails to handle excessive characters appended to the end of multipart boundaries. This | Mar 20, 2025 | 7.5 | 23 | NO | NO |
CVE-2024-12375MEDIUM A local file inclusion vulnerability was identified in automatic1111/stable-diffusion-webui, affecting version git 82a973c. This vulnerability allows an attacker to read arbitrary | Mar 20, 2025 | 6.5 | 19 | NO | NO |
CVE-2024-12074MEDIUM A Denial of Service (DoS) vulnerability was discovered in the file upload feature of automatic1111/stable-diffusion-webui version 1.10.0. The vulnerability is due to improper handl | Mar 20, 2025 | 6.5 | 19 | NO | NO |
CVE-2024-12374MEDIUM A stored cross-site scripting (XSS) vulnerability exists in automatic1111/stable-diffusion-webui version git 82a973c. An attacker can upload an HTML file, which the application int | Mar 20, 2025 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Automatic1111.
Media articles that mention a CVE ID that affects a product developed by Automatic1111 — matched by CVE ID, not by vendor name.