Configuration Tampering Vulnerability in ComfyUI-Manager by Comfy
CVE-2026-22777

7.5HIGH

Key Information:

Vendor

Comfy-org

Vendor
CVE Published:
10 January 2026

What is CVE-2026-22777?

CVE-2026-22777 represents a security vulnerability in ComfyUI-Manager, an extension aimed at improving the usability of ComfyUI, a user interface framework. This vulnerability specifically allows attackers to manipulate HTTP query parameters, leading to unauthorized modifications of the config.ini file. As a result, attackers can inject arbitrary configuration values, potentially impacting the application's security settings and behavior. Organizations utilizing ComfyUI-Manager versions prior to 3.39.2 and 4.0.5 should be particularly mindful of this risk, as it could lead to unauthorized access and manipulation of crucial operational settings.

Potential impact of CVE-2026-22777

  1. Security Setting Tampering: The vulnerability enables attackers to alter essential security configurations within the application, which may compromise the overall security of the system and create pathways for further attacks.

  2. Modification of Application Behavior: With the ability to inject arbitrary configurations, an attacker could change how the application operates, leading to unforeseen consequences that could disrupt business processes or expose sensitive data.

  3. Increased Attack Surface: Exploiting this vulnerability could allow for easier access points into the application and related systems, increasing the chances of larger-scale breaches and further exploitation by malicious actors.

Affected Version(s)

ComfyUI-Manager >= 4.0.0, < 4.0.5 < 4.0.0, 4.0.5

ComfyUI-Manager < 3.39.2 < 3.39.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.