CVE-2024-11045

A Cross-Site WebSocket Hijacking (CSWSH) vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows an attacker to clone a malicious server extension from a GitHub repository. The vulnerability arises from the lack of proper validation on WebSocket connections at ws://127.0.0.1:7860/queue/join, enabling unauthorized actions on the server. This can lead to unauthorized cloning of server extensions, execution of malicious scripts, data exfiltration, and potential denial of service (DoS).
CVSS

No CVSS.

References
Link Resource
https://huntr.com/bounties/b7ed0d87-0be5-4526-9b21-ffe0d39c283e Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:automatic1111:stable-diffusion-webui:1.10.0:*:*:*:*:*:*:*

History

05 Aug 2025, 16:26

Type Values Removed Values Added
References () https://huntr.com/bounties/b7ed0d87-0be5-4526-9b21-ffe0d39c283e - () https://huntr.com/bounties/b7ed0d87-0be5-4526-9b21-ffe0d39c283e - Exploit, Third Party Advisory
CWE CWE-346
CPE cpe:2.3:a:automatic1111:stable-diffusion-webui:1.10.0:*:*:*:*:*:*:*
First Time Automatic1111
Automatic1111 stable-diffusion-webui

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-08-05 16:26


NVD link : CVE-2024-11045

Mitre link : CVE-2024-11045


JSON object : View

Products Affected

automatic1111

  • stable-diffusion-webui
CWE
CWE-346

Origin Validation Error

CWE-284

Improper Access Control