VDB
Sign up
—

PYSEC-2025-9

Quick fix

PYSEC-2025-9 — invokeai: upgrade to the fixed version with the command below.

pip install --upgrade 'invokeai>=756008dc5899081c5aa51e5bd8f24c1b3975a59e'

Details

A remote code execution vulnerability exists in invoke-ai/invokeai versions 5.3.1 through 5.4.2 via the /api/v2/models/install API. The vulnerability arises from unsafe deserialization of model files using torch.load without proper validation. Attackers can exploit this by embedding malicious code in model files, which is executed upon loading. This issue is fixed in version 5.4.3.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/invokeai
Introduced in: 0Fixed in: 756008dc5899081c5aa51e5bd8f24c1b3975a59e
Fixpip install --upgrade 'invokeai>=756008dc5899081c5aa51e5bd8f24c1b3975a59e'

References