Description
to_abs_path in scripts/iib/tool.py normalised the requested path with os.path.normpath, which collapses dot segments but does not resolve symbolic links. A symlink placed inside a scanned directory therefore satisfies the containment comparison performed by is_path_trusted in scripts/iib/api.py while pointing outside that directory, and FileResponse follows the link when serving the response, so a link created in an image directory and targeting a file such as /etc/passwd discloses that file. Whether the check applies depends on get_enable_access_control in scripts/iib/tool.py: it returns true when IIB_ACCESS_CONTROL is set to enable, false when set to disable, and otherwise true when the host Stable Diffusion WebUI was started with share, ngrok, listen or server_name, falling back to false. Confinement is therefore active in the network-exposed WebUI deployments that rely on it, while a standalone run with no such option serves every readable file regardless of this flaw. The fix resolves the path with os.path.realpath.
Published: 2026-08-21
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: File Disclosure via Symbolic Link Escape
Action: Patch Now
AI Analysis

Impact

The vulnerability stems from the way the application normalises requested paths using os.path.normpath, which removes dot segments but does not resolve symbolic links. A symlink created inside a directory that the application scans can therefore point to a file outside that directory. This type of flaw is a path traversal / file inclusion weakness identified as CWE-59. The containment check performed by is_path_trusted compares the path string, not the resolved target; consequently FileResponse follows the symlink when serving the file, allowing an attacker to read arbitrary files such as /etc/passwd. The flaw exists wherever the access control flag is enabled, which occurs in network‑exposed WebUI deployments that use share, ngrok, listen or server_name. A standalone run without those options serves every readable file regardless of this defect, but the primary risk is focused on exposed deployments.

Affected Systems

This issue affects the open‑source Infinite Image Browsing plugin provided by zanllp. The description references code located in scripts/iib/api.py and scripts/iib/tool.py, and the vulnerability is present in the 1.8.0 release and earlier. No specific version range is listed, but any deployment running the vulnerable code base before the realpath fix is affected.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. EPSS is not available, and the flaw is not listed in the CISA KEV catalog. An attacker would need the ability to create a symlink inside a scanned directory, which can be achieved via file upload or local write access within the application’s context. Once in place, the attacker can read arbitrary files on the host system with the same privileges as the running process. The flaw is exploitable in network‑exposed deployments, making remediation urgent to prevent remote file disclosure.

Generated by OpenCVE AI on August 21, 2026 at 17:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a version that applies the realpath resolution fix in scripts/iib/tool.py
  • Disable the automatic access control by setting IIB_ACCESS_CONTROL to disable if the deployment cannot enforce it
  • Reconfigure or restrict the scanned directories so that only trusted users can write files or symlinks
  • Consider using a standalone run when network exposure is not required to avoid the confinement logic that triggers the flaw

Generated by OpenCVE AI on August 21, 2026 at 17:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Description to_abs_path in scripts/iib/tool.py normalised the requested path with os.path.normpath, which collapses dot segments but does not resolve symbolic links. A symlink placed inside a scanned directory therefore satisfies the containment comparison performed by is_path_trusted in scripts/iib/api.py while pointing outside that directory, and FileResponse follows the link when serving the response, so a link created in an image directory and targeting a file such as /etc/passwd discloses that file. Whether the check applies depends on get_enable_access_control in scripts/iib/tool.py: it returns true when IIB_ACCESS_CONTROL is set to enable, false when set to disable, and otherwise true when the host Stable Diffusion WebUI was started with share, ngrok, listen or server_name, falling back to false. Confinement is therefore active in the network-exposed WebUI deployments that rely on it, while a standalone run with no such option serves every readable file regardless of this flaw. The fix resolves the path with os.path.realpath.
Title Infinite Image Browsing Resolves Paths With normpath, Allowing Symlink Escape From Scanned Directories
First Time appeared Zanllp
Zanllp sd-webui-infinite Image Browsing
Weaknesses CWE-59
CPEs cpe:2.3:a:zanllp:sd-webui-infinite_image_browsing:*:*:*:*:*:*:*:*
Vendors & Products Zanllp
Zanllp sd-webui-infinite Image Browsing
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Zanllp Sd-webui-infinite Image Browsing
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-26T17:30:14.359Z

Reserved: 2026-08-21T14:14:43.821Z

Link: CVE-2026-77815

cve-icon Vulnrichment

Updated: 2026-08-26T17:30:06.564Z

cve-icon NVD

Status : Received

Published: 2026-08-21T15:16:47.883

Modified: 2026-08-26T18:17:03.027

Link: CVE-2026-77815

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T17:45:03Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')