CVE-2024-11045

CRITICAL

Automatic1111 Stable-diffusion-webui - Improper Access Control

Title source: rule
STIX 2.1

Description

A Cross-Site WebSocket Hijacking (CSWSH) vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows an attacker to clone a malicious server extension from a GitHub repository. The vulnerability arises from the lack of proper validation on WebSocket connections at ws://127.0.0.1:7860/queue/join, enabling unauthorized actions on the server. This can lead to unauthorized cloning of server extensions, execution of malicious scripts, data exfiltration, and potential denial of service (DoS).

Scores

CVSS v3 9.6
EPSS 0.0016
EPSS Percentile 36.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-284 CWE-346
Status published
Products (1)
automatic1111/stable-diffusion-webui 1.10.0
Published Mar 20, 2025
Tracked Since Feb 18, 2026