← advisory ledger

ADVISORY UNAUTH-2026-0035
TYPE cve
PRODUCT ComfyUI-Manager
SEVERITY CRITICAL

CRITICAL

ComfyUI-Manager CVE-2025-67303

published 2026-08-05 · updated 2026-08-05

Why it matters

Data and configuration directories are not protected by the ComfyUI web API access control. An unauthenticated attacker can overwrite the manager config (security_level=weak) and install a malicious custom node, achieving remote code execution.

Affected versions

  • <3.38

Fixed in: 3.38

Mapping provenance: human-verified against the linked advisory, last checked 2026-07-29.

Fix it

Fix card: cve-2025-67303 →

References

Cite this record

unauth.dev advisory UNAUTH-2026-0035 — published 2026-08 · CC-BY 4.0

Canonical URL: https://unauth.dev/advisories/UNAUTH-2026-0035. This record is part of the unauth.dev advisory dataset, published under CC-BY 4.0: attribute "unauth.dev / Raúl Acedo". Schema: additive-only within v1; this id will never be renumbered or reused.