Cross-Site Request Forgery Vulnerability in ComfyUI by ComfyAnonymous
CVE-2024-10481
6.5MEDIUM
What is CVE-2024-10481?
A critical security flaw exists in ComfyUI versions up to v0.2.2 that exposes users to Cross-Site Request Forgery (CSRF) attacks. Malicious actors can host deceptive websites that, when accessed by authenticated ComfyUI users, can execute arbitrary API requests on their behalf. This vulnerability primarily affects API endpoints like '/upload/image', '/prompt', and '/history', which lack adequate CSRF protections. Attackers could exploit this weakness to conduct unauthorized actions such as uploading malicious files, potentially leading to further compromises, especially when combined with vulnerabilities like stored XSS that could jeopardize user sessions.
Affected Version(s)
comfyanonymous/comfyui <= unspecified
