An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration and critical data. This was due to the application storing its files in an insufficiently protected location that was accessible via the web interface
Metrics
Affected Vendors & Products
References
History
Fri, 30 Jan 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Comfy comfyui-manager
|
|
| CPEs | cpe:2.3:a:comfy:comfyui-manager:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Comfy comfyui-manager
|
Tue, 06 Jan 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Comfy
Comfy comfyui |
|
| Vendors & Products |
Comfy
Comfy comfyui |
Mon, 05 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-420 | |
| Metrics |
cvssV3_1
|
Mon, 05 Jan 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration and critical data. This was due to the application storing its files in an insufficiently protected location that was accessible via the web interface | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-01-05T00:00:00.000Z
Updated: 2026-01-05T19:11:15.458Z
Reserved: 2025-12-08T00:00:00.000Z
Link: CVE-2025-67303
Updated: 2026-01-05T19:10:07.476Z
Status : Analyzed
Published: 2026-01-05T16:15:42.977
Modified: 2026-01-30T01:31:37.653
Link: CVE-2025-67303
No data.