CVE-2024-10099 is a stored cross-site scripting (XSS) vulnerability affecting comfyanonymous/comfyui version 0.2.2 and potentially earlier. An attacker can upload a malicious HTML file via the /api/upload/image endpoint, and the embedded XSS payload executes when viewed through the /view API, allowing arbitrary JavaScript execution. With a CVSS score of 6.1 (MEDIUM), this vulnerability requires user interaction (UI:R) but has low attack complexity (AC:L) and no authentication (PR:N). There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in the KEV catalog, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.2.2CPE matchmatch criteria | cpe:2.3:a:comfy:comfyui:0.2.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.