Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-22777

Опубликовано: 10 янв. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

ComfyUI-Manager is an extension designed to enhance the usability of ComfyUI. Prior to versions 3.39.2 and 4.0.5, an attacker can inject special characters into HTTP query parameters to add arbitrary configuration values to the config.ini file. This can lead to security setting tampering or modification of application behavior. This issue has been patched in versions 3.39.2 and 4.0.5.

EPSS

Процентиль: 12%
0.0004
Низкий

7.5 High

CVSS3

Дефекты

CWE-93

Связанные уязвимости

CVSS3: 7.5
github
6 дней назад

ComfyUI-Manager is Vulnerable to CRLF Injection in Configuration Handler

EPSS

Процентиль: 12%
0.0004
Низкий

7.5 High

CVSS3

Дефекты

CWE-93