Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rjx4-8gxj-w5gj

Опубликовано: 13 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 10
CVSS3: 10

Описание

ComfyUI-Ace-Nodes is vulnerable to Code Injection. The ACE_ExpressionEval node contains an eval() in its entrypoint function that accepts arbitrary user-controlled data. A user can create a workflow that results in executing arbitrary code on the server.

ComfyUI-Ace-Nodes is vulnerable to Code Injection. The ACE_ExpressionEval node contains an eval() in its entrypoint function that accepts arbitrary user-controlled data. A user can create a workflow that results in executing arbitrary code on the server.

EPSS

Процентиль: 37%
0.00162
Низкий

10 Critical

CVSS4

10 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 10
nvd
около 1 года назад

ComfyUI-Ace-Nodes is vulnerable to Code Injection. The ACE_ExpressionEval node contains an eval() in its entrypoint function that accepts arbitrary user-controlled data. A user can create a workflow that results in executing arbitrary code on the server.

EPSS

Процентиль: 37%
0.00162
Низкий

10 Critical

CVSS4

10 Critical

CVSS3

Дефекты

CWE-94