CVE-2024-21575 - ComfyUI Path Traversal RCE
CVE ID : CVE-2024-21575 Published : Dec. 12, 2024, 3:15 p.m. | 1 hour, 44 minutes ago Description : ComfyUI-Impact-Pack is vulnerable to Path Traversal. The issue stems from missing validation of the `image.filename` field in a POST request sent to the `/upload/temp` endpoint added by the extension to the server. This results in writing arbitrary files to the file system which may, under some conditions, result in remote code execution (RCE). Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Dec. 12, 2024, 3:15 p.m. | 1 hour, 44 minutes ago
Description : ComfyUI-Impact-Pack is vulnerable to Path Traversal. The issue stems from missing validation of the `image.filename` field in a POST request sent to the `/upload/temp` endpoint added by the extension to the server. This results in writing arbitrary files to the file system which may, under some conditions, result in remote code execution (RCE).
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...