Bounties
Partners
Community
Info
comfyanonymous / comfyui
Project repository
The most powerful and modular diffusion model GUI, api and backend with a graph/nodes interface.
Submit a report
FIRST INTERACTION
WITHIN
N/A DAYS
REVIEW
WITHIN
34 DAYS
FIX
WITHIN
N/A DAYS
Deserializing unsafe data in comfyui leads to RCE
Feb 13th 2025
l1k3beef
•
duplicate
Critical
DNS Rebinding
Feb 21st 2025
sanktjodel
•
pending
SSRF via POST /internal/models/download and GET /view REST APIs
Jan 21st 2025
zpbrent
•
High
•
$450
High
•
$450
•
CVE-2024-12882
CVE-2024-12882
Cross-Site Request Forgery to XSS at workflow
Dec 19th 2024
srivallikusumba
•
duplicate
High
Cross-Site Request Forgery to XSS
Dec 18th 2024
srivallikusumba
•
duplicate
High
RCE via pickle deserialization (unpickling)
Oct 21st 2024
seqode
•
informative
High
Denial of service via CSRF
Dec 15th 2024
seqode
•
duplicate
Medium
Default CORS settings leads to sensitive data exfiltration
Oct 28th 2024
ethansilvas
•
informative
Medium
Unrestricted Upload of File with Dangerous Type
Oct 28th 2024
seqode
•
duplicate
Critical
CSRF allows for requests on behalf of authenticated users
Dec 14th 2024
ethansilvas
•
Medium
Medium
•
CVE-2024-10481
CVE-2024-10481
XSS through viewing HTML files with /view
Sep 14th 2024
ethansilvas
•
Medium
Medium
•
CVE-2024-10099
CVE-2024-10099
Race Condition Vulnerability: Concurrent File Overwrite Leading to Data Integrit...
Oct 21st 2024
morphykutay
•
informative
Medium
Delete any file on the system
Sep 13th 2024
hainguyen0207
•
self closed
Path Traversal in API `/userdata/{file}
Nov 26th 2024
duongli99
•
not applicable
closed
Sep 13th 2024
kienzx203
•
self closed
CRITICAL
$0
HIGH
$0
MEDIUM
$0
LOW
$0