CVE-2026-65012 | invoke-ai InvokeAI up to 6.13.6 scan_folder scan_path access control

SecurityVulns

A vulnerability has been found in invoke-ai InvokeAI up to 6.13.6 and classified as problematic. This vulnerability affects unknown code of the file /api/v2/models/scan_folder of the component scan_folder. The manipulation of the argument scan_path leads to improper access controls.

This vulnerability is referenced as CVE-2026-65012. Remote exploitation of the attack is possible. No exploit is available.

The affected component should be upgraded.VulDB Recent EntriesRead More