{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aautomatic1111stable_diffusion_webui/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:automatic1111:stable_diffusion_webui:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-82288"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Stable Diffusion WebUI (\u003c= 1.10.1)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","credential-disclosure","web-api"],"_cs_type":"threat","_cs_vendors":["Automatic1111"],"content_html":"\u003cp\u003eStable Diffusion WebUI versions through 1.10.1 contain a significant credential disclosure vulnerability located within the /sdapi/v1/cmd-flags endpoint. This endpoint, intended for administrative visibility, improperly exposes parsed command-line arguments to any unauthenticated user who sends a request to the API. Specifically, the response includes the gradio_auth and api_auth configuration parameters, which frequently contain usernames and passwords defined at startup to secure the application. An attacker with network access to the Stable Diffusion instance can exploit this flaw to bypass authentication controls, potentially gaining full control over the AI image generation interface. This represents a critical risk for deployments exposed to the internet or untrusted internal networks, as it allows for trivial credential harvesting without requiring prior access or interaction.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the exposure of administrative or user credentials, enabling unauthorized access to the application interface. This can lead to the unauthorized execution of compute-intensive image generation tasks, modification of system configurations, or exfiltration of sensitive generated content. Organizations hosting Stable Diffusion WebUI instances that rely on these authentication flags for basic access control are at risk of complete account takeover.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade Stable Diffusion WebUI to a version post-1.10.1 that remediates this information disclosure.\u003c/li\u003e\n\u003cli\u003eImplement strict network-level access controls to ensure the web application and its API endpoints are not reachable from the public internet.\u003c/li\u003e\n\u003cli\u003eDeploy the webserver-level detection rule provided below to identify unauthorized scanning or direct requests to the vulnerable API path.\u003c/li\u003e\n\u003cli\u003eRotate any credentials identified in the command-line arguments (gradio_auth and api_auth) if the system has been accessible to untrusted parties.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-28T21:41:01Z","date_published":"2026-08-28T21:41:01Z","id":"https://feed.craftedsignal.io/briefs/2026-08-stable-diffusion-credential-disclosure/","summary":"Stable Diffusion WebUI versions 1.10.1 and earlier contain a credential disclosure vulnerability allowing unauthenticated remote attackers to retrieve cleartext authentication credentials.","title":"Credential Disclosure in Stable Diffusion WebUI via /sdapi/v1/cmd-flags","url":"https://feed.craftedsignal.io/briefs/2026-08-stable-diffusion-credential-disclosure/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:automatic1111:stable_diffusion_webui:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}