CVE-2026-77814: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in zanllp infinite-image-browsing
Description
is_path_trusted in scripts/iib/api.py compares the requested path against each allowed parent directory with path.startswith(parent_path), without appending a path separator. A directory whose name merely begins with an allowed path therefore satisfies the comparison, so where /data/images is allowed a request for /data/images_private/secret.txt is treated as trusted and served by FileResponse, disclosing files the confinement was meant to exclude. Whether the check applies depends on get_enable_access_control in scripts/iib/tool.py: it returns true when IIB_ACCESS_CONTROL is set to enable, false when set to disable, and otherwise true when the host Stable Diffusion WebUI was started with share, ngrok, listen or server_name, falling back to false. Confinement is therefore active in the network-exposed WebUI deployments that rely on it, while a standalone run with no such option serves every readable file regardless of this flaw. The fix compares against parent_path joined with os.sep.
CVSS v4.0
Score 8.7high
Affected software
zanllp
infinite-image-browsing
pkg:github/infinite-image-browsingRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability arises from the is_path_trusted function in scripts/iib/api.py, which uses path.startswith(parent_path) without appending a path separator, causing directories with names beginning with allowed paths to be mistakenly trusted. For example, if /data/images is allowed, a request for /data/images_private/secret.txt is incorrectly served, disclosing unauthorized files. Access control depends on the get_enable_access_control function, which returns true or false based on environment variables and startup options. The issue is fixed by comparing against parent_path joined with os.sep to ensure exact directory matching.
Potential Impact
An attacker can exploit this flaw to access and disclose files outside the intended restricted directories, potentially exposing sensitive information. This affects network-exposed WebUI deployments that rely on the access control mechanism. Standalone runs without these options serve all readable files regardless of the flaw, increasing exposure. The CVSS 4.0 score is 8.7 (high severity), indicating a significant risk of unauthorized file disclosure without requiring privileges or user interaction.
Mitigation Recommendations
A fix is available that corrects the path validation by appending the path separator to parent_path before comparison. Users should upgrade to a version that includes this fix. Since no explicit patch link is provided, check the vendor's advisory or repository for the updated version. Until patched, avoid exposing the WebUI with network options that enable access control or restrict access to trusted users only.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-21T14:14:43.820Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a8869e8acd9273b494e4711
Added to database: 08/21/2026, 15:08:24 UTC
Last enriched: 09/25/2026, 02:42:21 UTC
Last updated: 10/05/2026, 06:48:18 UTC
Views: 63
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.