An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This vulnerability can be exploited to conduct phishing attacks, distribute malware, and steal user credentials.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-7060 An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This vulnerability can be exploited to conduct phishing attacks, distribute malware, and steal user credentials.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 05 Aug 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Automatic1111
Automatic1111 stable-diffusion-webui
CPEs cpe:2.3:a:automatic1111:stable-diffusion-webui:1.10.0:*:*:*:*:*:*:*
Vendors & Products Automatic1111
Automatic1111 stable-diffusion-webui

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00807}

epss

{'score': 0.0092}


Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00552}

epss

{'score': 0.00807}


Thu, 20 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Mar 2025 10:15:00 +0000

Type Values Removed Values Added
Description An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This vulnerability can be exploited to conduct phishing attacks, distribute malware, and steal user credentials.
Title Open Redirect in automatic1111/stable-diffusion-webui
Weaknesses CWE-601
References
Metrics cvssV3_0

{'score': 6.1, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published:

Updated: 2025-03-20T18:37:59.803Z

Reserved: 2024-11-09T06:44:19.821Z

Link: CVE-2024-11044

cve-icon Vulnrichment

Updated: 2025-03-20T17:50:45.909Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-20T10:15:23.760

Modified: 2025-08-05T16:40:28.587

Link: CVE-2024-11044

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.