Cross-Site Request Forgery Vulnerability in ComfyUI by ComfyAnonymous
CVE-2024-10481
What is CVE-2024-10481?
A critical security flaw exists in ComfyUI versions up to v0.2.2 that exposes users to Cross-Site Request Forgery (CSRF) attacks. Malicious actors can host deceptive websites that, when accessed by authenticated ComfyUI users, can execute arbitrary API requests on their behalf. This vulnerability primarily affects API endpoints like '/upload/image', '/prompt', and '/history', which lack adequate CSRF protections. Attackers could exploit this weakness to conduct unauthorized actions such as uploading malicious files, potentially leading to further compromises, especially when combined with vulnerabilities like stored XSS that could jeopardize user sessions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
comfyanonymous/comfyui <= unspecified
References
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
