Infinite Image Browsing fixed two related path validation flaws that could let remote attackers read files outside intended directories in deployments exposed through Stable Diffusion WebUI. The issues, tracked as CVE-2026-77814 and CVE-2026-77815, affect versions through 1.8.0 and stem from the is_path_trusted() logic in scripts/iib/api.py and path resolution in scripts/iib/tool.py. One bug used a naive startswith(parent_path) check, allowing prefix-collision bypasses such as trusted /data/images matching /data/images_private; the other relied on os.path.normpath(), which failed to resolve symlinks and enabled escapes from scanned directories to disclose readable files such as /etc/passwd.
The project merged a fix in pull request #969 and commit 4057a624c7a23a36f0b4dc6a545b40767d602450, replacing os.path.normpath() with os.path.realpath() and tightening validation to require the trusted parent path plus a trailing separator. The patch also ensures resolved paths are used for file serving, addressing CWE-22 and CWE-59. The original report noted that some standalone configurations had enable_access_control = False by default, while network-exposed WebUI modes such as share, ngrok, listen, or server_name could automatically enable access control and therefore depend on the flawed confinement checks.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-77815 was published for a CWE-59 arbitrary file disclosure flaw in Infinite Image Browsing affecting versions up to and including 1.8.0. The CVE describes how os.path.normpath() in to_abs_path failed to resolve symlinks, enabling files outside scanned directories to be disclosed via symlink targets.
CVE-2026-77814 was published for a CWE-22 information disclosure flaw in Infinite Image Browsing affecting versions up to and including 1.8.0. The CVE describes how is_path_trusted() used path.startswith(parent_path) without a trailing separator, allowing unauthorized file access outside the intended directory boundary.
A pull request and merge commit updated Infinite Image Browsing to use os.path.realpath() and require startswith(parent_path + os.sep), addressing both symlink escape and prefix-matching bypasses. The patch modified scripts/iib/api.py and scripts/iib/tool.py and was merged into the main branch.
A GitHub issue documented two file access control bypasses in Infinite Image Browsing: a prefix-collision flaw in is_path_trusted() and a symlink escape caused by using os.path.normpath() without resolving links. The report also noted that the default standalone configuration disables access control, allowing unauthenticated reading of files.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.