Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
invoke-ai InvokeAI — InvokeAI < 6.13.7 Unauthenticated Directory Enumeration via scan_folder
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L P N N L N N 6.3 .0026 17.5 —
AFFECTED
Product Versions Fixed
InvokeAI unspecified —
TIMELINE
Jul 21 Reserved by VulnCheck
Jul 22 Published (CNA: VulnCheck)
Jul 23 EXPLOIT PUBLISHED — CVE-2026-65012 (invoke-ai InvokeAI). Public exploit reference added.
Jul 24 EXPLOIT PUBLISHED — CVE-2026-65012 (invoke-ai InvokeAI). Public exploit reference added.
Description
InvokeAI before 6.13.7 contains an unauthenticated directory enumeration vulnerability in the GET /api/v2/models/scan_folder endpoint that accepts attacker-controlled scan_path parameters. Unauthenticated attackers can recursively enumerate arbitrary server filesystem directories and use HTTP response codes to determine file existence and readability, bypassing multi-user mode access controls.
Lifecycle
Complete event history — 4 events, chronological
| Date | Event | Detail |
| July 21, 2026 | Reserved | Reserved by VulnCheck |
| July 22, 2026 | Published | Published (CNA: VulnCheck) |
| July 23, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-65012 (invoke-ai InvokeAI). Public exploit reference added. |
| July 24, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-65012 (invoke-ai InvokeAI). Public exploit reference added. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| invoke-ai | InvokeAI | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-65012 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.