We found results for “”
CVE-2025-67303
Good to know:
Date: January 4, 2026
An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration and critical data. This was due to the application storing its files in an insufficiently protected location that was accessible via the web interface
Severity Score
Related Resources (4)
Severity Score
Weakness Type (CWE)
Unprotected Alternate Channel
CWE-420Top Fix
Upgrade Version
Upgrade to version comfyui-manager - 4.0.3;https://github.com/Comfy-Org/ComfyUI-Manager.git - 3.38
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | HIGH |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


