Bmaltais maintains Kohya SS, a specialized machine-learning training tool for image generation models, whose vulnerability profile skews strongly toward critical-severity outcomes across a narrow but focused product scope. The recurring weakness classes—command injection and path traversal—reflect the tool's interaction with system-level file operations and external process execution, which represent characteristic attack surfaces in training and inference pipelines. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bmaltais over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-32027CRITICAL Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss v22.6.1 is vulnerable to command injection in `finetune_gui.py` This vulnerability is fixed in 23.1.5. | Apr 16, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-32022CRITICAL Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to command injection in basic_caption_gui.py. This vulnerability is fixed in 23.1.5. | Apr 16, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-32026CRITICAL Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a command injection in `git_caption_gui.py`. This vulnerability is fixed in 23.1.5. | Apr 16, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-32025CRITICAL Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a command injection in `group_images_gui.py`. This vulnerability is fixed in 23.1.5. | Apr 16, 2024 | 9.1 | 26 | NO | NO |
CVE-2024-32024MEDIUM Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a path injection in the `common_gui.py` `add_pre_postfix` function. This vulnerability is fixed i | Apr 16, 2024 | 6.5 | 20 | NO | NO |
CVE-2024-32023MEDIUM Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a path injection in the `common_gui.py` `find_and_replace` function. This vulnerability is fixed | Apr 16, 2024 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bmaltais.
Media articles that mention a CVE ID that affects a product developed by Bmaltais — matched by CVE ID, not by vendor name.