CVE-2024-11044
Published: 20 March 2025
Summary
CVE-2024-11044 is a medium-severity Open Redirect (CWE-601) vulnerability in Automatic1111 Stable-Diffusion-Webui. Its CVSS base score is 6.1 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked in the top 19.3% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
This vulnerability is AI-related — categorised as LLM Application Platforms; in the Supply Chain and Deployment risk domain.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-7060
Vulnerability details
An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This vulnerability can be exploited to conduct phishing attacks, distribute malware, and steal user credentials.
- CWE(s)
AI Security AnalysisAI
- AI Category
- LLM Application Platforms
- Risk Domain
- Supply Chain and Deployment
- OWASP Top 10 for LLMs 2025
- None mapped
- Classification Reason
- Matched keywords: automatic1111, stable-diffusion-webui
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
The open redirect vulnerability enables exploitation of a public-facing web application (T1190) and facilitates spearphishing links by redirecting users to arbitrary malicious websites for phishing, malware distribution, and credential theft (T1566.002).
Affected Assets
Mitigating Controls
Likely Mitigating Controls AI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.