Cross-Site Request Forgery Vulnerability in ComfyUI by ComfyAnonymous
CVE-2024-10481

6.5MEDIUM

Key Information:

Vendor
CVE Published:
20 March 2025

What is CVE-2024-10481?

A critical security flaw exists in ComfyUI versions up to v0.2.2 that exposes users to Cross-Site Request Forgery (CSRF) attacks. Malicious actors can host deceptive websites that, when accessed by authenticated ComfyUI users, can execute arbitrary API requests on their behalf. This vulnerability primarily affects API endpoints like '/upload/image', '/prompt', and '/history', which lack adequate CSRF protections. Attackers could exploit this weakness to conduct unauthorized actions such as uploading malicious files, potentially leading to further compromises, especially when combined with vulnerabilities like stored XSS that could jeopardize user sessions.

Affected Version(s)

comfyanonymous/comfyui <= unspecified

References

CVSS V3.0

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.