S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 28, 2025

CVE-2024-11044 Scanner

CVE-2024-11044 Scanner - Open Redirect vulnerability in Stable Diffusion Webui

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.4k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-11044
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This vulnerability can be exploited to conduct phishing attacks, distribute malware, and steal user credentials.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
automatic1111/stable-diffusion-webuiby automatic1111
unspecified
Updated Aug 22, 2026View on NVD →
Detail

Stable Diffusion Webui is an open-source interface for deploying and managing AI-based image generation models. It is widely utilized by developers, artists, and enthusiasts to create and refine AI-generated artwork. The platform supports advanced features such as custom model integration, user-friendly settings, and extensibility through plugins. Its flexibility and accessibility have made it a popular choice for creative AI applications.

The vulnerability identified in Stable Diffusion Webui v1.10.0 is an Open Redirect flaw. This issue allows attackers to exploit the "file" parameter in the "/file=" endpoint to redirect users to unauthorized or malicious websites. Such vulnerabilities pose serious risks as users may unknowingly access phishing sites or download malicious files, leading to data theft or system compromise. Addressing this issue is essential to maintain user trust and security.

The vulnerability arises from inadequate input validation in the "file" parameter. When crafted URLs are sent to the "/file=" endpoint, the system processes the parameter without proper sanitization, enabling redirection to external domains. This improper handling of user-supplied input creates an opportunity for attackers to conduct malicious activities by embedding harmful links. Robust input validation is critical to preventing such exploits.

Exploitation of this vulnerability can lead to phishing attacks, malware installations, and potential data breaches. Users redirected to malicious websites may inadvertently expose sensitive information or compromise their systems. The reputation of Stable Diffusion Webui as a secure tool could also be adversely affected, reducing user confidence in the platform.

REFERENCES

Solution Advice
  • Validate and sanitize user-supplied input for the "file" parameter.
  • Restrict redirections to a predefined whitelist of trusted domains.
  • Apply server-side checks to reject untrusted or malformed URLs.
  • Update Stable Diffusion Webui to the latest version with a patch for this vulnerability.
  • Conduct regular security assessments to detect and resolve potential vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.