Skip to content

[Security] Request contact info to report multiple vulnerabilities (deserialization/SSRF/RCE, etc.) #756

@lihuss

Description

@lihuss

@lllyasviel , hello.

During my usage/audit of this project, I discovered several security-related issues:

YAML deserialization vulnerability (yaml.load can lead to arbitrary code execution)

Torch model deserialization vulnerability (torch.load can lead to RCE)

SSRF / arbitrary URL request vulnerability (urlopen without validation can access internal resources)

Pickle deserialization vulnerability (pickle.load can lead to RCE)

Since these vulnerability details should not be disclosed publicly, could you please provide a private contact method (e.g., email, temporary chat, or a private issue) so that I can send you the full details, exploit chains, and suggested fixes?

Thank you for your open source work. Looking forward to your reply.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions