CVE-2026-65012
MEDIUMInvokeAI < 6.13.7 Unauthenticated Directory Enumeration via scan_folder
Title source: cnaDescription
InvokeAI before 6.13.7 contains an unauthenticated directory enumeration vulnerability in the GET /api/v2/models/scan_folder endpoint that accepts attacker-controlled scan_path parameters. Unauthenticated attackers can recursively enumerate arbitrary server filesystem directories and use HTTP response codes to determine file existence and readability, bypassing multi-user mode access controls.
References (5)
Core 5
Core References
Exploit technical-description
exploit
issue-tracking
Researcher Disclosure
https://github.com/invoke-ai/InvokeAI/issues/9365
Release Notes release-notes
patch
Release Notes
https://github.com/invoke-ai/InvokeAI/releases/tag/v6.13.7
Patch patch
Patch Commit
https://github.com/invoke-ai/InvokeAI/commit/d315b8967f548732912bd9b390853ed4af97d8cb
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/invokeai-unauthenticated-directory-enumeration-via-scan-folder
Scores
CVSS v3
5.3
EPSS
0.0026
EPSS Percentile
17.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-306
Status
published
Products (1)
invoke-ai/InvokeAI
< 6.13.7
Published
Jul 22, 2026
Tracked Since
Jul 22, 2026