CVE-2024-12029 is a remote code execution vulnerability in invoke-ai/invokeai versions 5.3.1 through 5.4.2. The vulnerability is present in the /api/v2/models/install API endpoint, which uses torch.load to deserialize model files without proper validation. This allows attackers to craft malicious model files containing arbitrary code, which is executed when the file is loaded by the vulnerable API endpoint.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, focused exploit kit for testing and exploiting unsafe deserialization in InvokeAI, explicitly referencing CVE-2024-12029. It contains two Python scripts and a README. The main purpose is to generate malicious pickle-based checkpoint files and then deliver them to the InvokeAI model installation API to confirm remote code execution or obtain shell access. Repository structure: README.md documents the attack flow, expected payload files, and manual usage examples. reverse_shell_payload.py is the payload generator; it defines multiple Python classes whose __reduce__ methods return os.system invocations so that arbitrary commands execute when the object is deserialized. It generates four .ckpt payloads: bash reverse shell, Python reverse shell, netcat reverse shell, and HTTP callback test. kali_reverse_test.py is an operator helper script that sends POST requests to the target InvokeAI endpoint /api/v2/models/install with a source parameter pointing to attacker-hosted payload files, and optionally starts a local netcat listener. Exploit capabilities: (1) verify deserialization/RCE via HTTP callback to attacker web server, (2) gain interactive shell access via reverse shell over TCP/4444 using bash, Python, or netcat, and (3) verify basic command execution by creating a marker file on the target. The exploit is operational rather than a mere PoC because it includes working payload generation and delivery logic, but payload customization is basic and hardcoded around specific IPs and ports. Notable endpoints and targets: the target API is hardcoded as http://192.168.117.218:9090/api/v2/models/install. Attacker infrastructure is hardcoded as 192.168.45.168, serving payloads over HTTP on port 8000 and receiving reverse shells on TCP/4444. The code also references /tmp/payload_test.txt as a local artifact on the victim for execution verification. Overall, this is a genuine exploit repository centered on web-triggered unsafe deserialization leading to OS command execution and reverse shell establishment.
This repository contains a single Metasploit module targeting CVE-2024-12029, a critical remote code execution vulnerability in InvokeAI (versions 4.0.0 to 5.4.2) on Linux. The exploit abuses the /api/v2/models/install API endpoint, which unsafely deserializes user-supplied model files using torch.load, allowing attackers to execute arbitrary code by supplying a malicious model file. The module checks the target's version via /api/v1/app/version, then serves a malicious model file via an embedded HTTP server, and finally triggers the vulnerable endpoint to load the file, resulting in code execution. The payload is customizable and leverages Python deserialization to execute arbitrary commands. The exploit is weaponized, as it is part of the Metasploit framework and supports flexible payload delivery. The only file present is a Ruby Metasploit module, and the main attack vector is network-based, targeting HTTP endpoints exposed by InvokeAI.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.