CVE-2024-10481 is a Cross-Site Request Forgery (CSRF) vulnerability affecting comfyanonymous/comfyui versions up to v0.2.2. Attackers can leverage this by hosting malicious websites that, when visited by an authenticated ComfyUI user, can force the user's browser to make unauthorized API requests, such as uploading arbitrary files. Rated 6.5 Medium (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N), this vulnerability requires user interaction (UI:R) but has low attack complexity (AC:L) and can lead to high integrity impact (I:H) by allowing unauthorized actions. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.2.2CPE matchmatch criteria | cpe:2.3:a:comfy:comfyui:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.