Skip to content

Command injection in `group_images_gui.py` (`GHSL-2024-021`)

Critical
bmaltais published GHSA-qprv-9pg5-h33c Apr 12, 2024

Package

No package listed

Affected versions

v22.6.1 - v23.1.3

Patched versions

v24.0.1+

Description

Summary

Kohya_ss v22.6.1 is vulnerable to command injection in group_images_gui.py

Fix commit: 831af8b

Severity

Critical

CVE ID

CVE-2024-32025

Weaknesses

Credits