CVE-2024-11044 MEDIUM

CVE-2024-11044: Open Redirect in automatic1111/stable-diffusion-webui

Vendor Automatic1111
Product automatic1111/stable-diffusion-webui
Weakness CWE-601 · Open redirect
Published March 20, 2025
Last update March 20, 2025

CVSS base score

6.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

What the vulnerability does

01Description

An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This vulnerability can be exploited to conduct phishing attacks, distribute malware, and steal user credentials.

Key dates

02Disclosure timeline

March 20, 2025 CVE published
March 20, 2025 Record updated