Vulnerability in ComfyUI-Impact-Pack Could Lead to Remote Code Execution
CVE-2024-21575
8.6HIGH
What is CVE-2024-21575?
The ComfyUI-Impact-Pack extension contains a Path Traversal vulnerability due to inadequate validation of the image.filename
parameter in POST requests directed to the /upload/temp
endpoint. This flaw allows attackers to manipulate the file paths, writing arbitrary files to the server's filesystem. In certain scenarios, this vulnerability can escalate to remote code execution, potentially compromising the entire system. Users and admins of affected versions are advised to implement immediate remediation measures and monitor for any unauthorized file uploads.
Affected Version(s)
ComfyUI-Impact-Pack 0 < 7.6.2