Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2hc9-cc65-xwj8

Опубликовано: 05 янв. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Duplicate Advisory: ComfyUI-Manager has an Unprotected Alternate Channel (CWE-420)

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-95pq-hr8p-f5g7. This link is maintained to preserve external references.

Original Description

An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration and critical data. This was due to the application storing its files in an insufficiently protected location that was accessible via the web interface

Пакеты

Наименование

comfyui-manager

pip
Затронутые версииВерсия исправления

< 3.38

3.38

7.5 High

CVSS3

Дефекты

CWE-420

7.5 High

CVSS3

Дефекты

CWE-420