InvokeAI Version 6.13.8
⚠️ This is a security patch release
Recent versions of InvokeAI through 6.13.7 contain two security holes:
- An attacker can craft a URL payload that overwrites files in the server's custom nodes directory, allowing for execution of arbitrary code on the next startup. On Windows systems, the hole could allow an arbitrary file to be placed anywhere on the filesystem that the server has access to.
- A second bugs allows the server to be tricked into connecting to arbitrary networks and services on the local LAN or the Internet.
Both scenarios are closed by this release, and InvokeAI users are strongly encouraged to upgrade.
Many thanks to Abhinash Singh and Arpit Jain for independently reporting issue #1.
Full Changelog: v6.13.7...v6.13.8