Security Advisory

CVE-2024-12882

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-03-20 10:10:31
Last updated 2025-03-20 18:20:26
Assigner @huntr_ai
CVSS score 7.5
State PUBLISHED

Description

comfyanonymous/comfyui version v0.2.4 suffers from a non-blind Server-Side Request Forgery (SSRF) vulnerability. This vulnerability can be exploited by combining the REST APIs `POST /internal/models/download` and `GET /view`, allowing attackers to abuse the victim server's credentials to access unauthorized web resources.