CVE-2024-12029 | invoke-ai invokeai up to 5.4.2 API /api/v2/models/install deserialization
A vulnerability was found in invoke-ai invokeai up to 5.4.2 and classified as very critical. This issue affects some unknown processing of the file /api/v2/models/install of the component API. The manipulation leads to deserialization.
The identification of this vulnerability is CVE-2024-12029. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.