Heap-based Buffer Overflow Affecting leejet/stable-diffusion.cpp package, versions [,master-584-0a7ae07)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.18% (8th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Heap-based Buffer Overflow vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-UNMANAGED-LEEJETSTABLEDIFFUSIONCPP-17660922
  • published28 Jun 2026
  • disclosed16 Jun 2026
  • creditUnknown

Introduced: 16 Jun 2026

CVE-2026-47747  (opens in a new tab)
CWE-122  (opens in a new tab)

How to fix?

Upgrade leejet/stable-diffusion.cpp to version master-584-0a7ae07 or higher.

Overview

Affected versions of this package are vulnerable to Heap-based Buffer Overflow via the BINUNICODE opcode handler in the pickle .ckpt parser due to sign confusion on the opcode length field. An attacker can achieve heap corruption and potentially execute arbitrary code or cause a crash by supplying a crafted .ckpt file containing a negative signed value that leads to an excessively large length in a memcpy operation.

Workaround

This vulnerability can be mitigated by only loading .ckpt checkpoint files from trusted sources and preferring trusted model sources and safer formats such as .safetensors.

CVSS Base Scores

version 4.0
version 3.1