Логотип exploitDog
bind:CVE-2024-21577
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-21577

Количество 2

Количество 2

nvd логотип

CVE-2024-21577

около 1 года назад

ComfyUI-Ace-Nodes is vulnerable to Code Injection. The ACE_ExpressionEval node contains an eval() in its entrypoint function that accepts arbitrary user-controlled data. A user can create a workflow that results in executing arbitrary code on the server.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-rjx4-8gxj-w5gj

около 1 года назад

ComfyUI-Ace-Nodes is vulnerable to Code Injection. The ACE_ExpressionEval node contains an eval() in its entrypoint function that accepts arbitrary user-controlled data. A user can create a workflow that results in executing arbitrary code on the server.

CVSS3: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-21577

ComfyUI-Ace-Nodes is vulnerable to Code Injection. The ACE_ExpressionEval node contains an eval() in its entrypoint function that accepts arbitrary user-controlled data. A user can create a workflow that results in executing arbitrary code on the server.

CVSS3: 10
0%
Низкий
около 1 года назад
github логотип
GHSA-rjx4-8gxj-w5gj

ComfyUI-Ace-Nodes is vulnerable to Code Injection. The ACE_ExpressionEval node contains an eval() in its entrypoint function that accepts arbitrary user-controlled data. A user can create a workflow that results in executing arbitrary code on the server.

CVSS3: 10
0%
Низкий
около 1 года назад

Уязвимостей на страницу