CVE-2025-67303

An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration and critical data. This was due to the application storing its files in an insufficiently protected location that was accessible via the web interface
Configurations

Configuration 1 (hide)

cpe:2.3:a:comfy:comfyui-manager:*:*:*:*:*:*:*:*

History

30 Jan 2026, 01:31

Type Values Removed Values Added
First Time Comfy
Comfy comfyui-manager
References () https://github.com/Comfy-Org/ComfyUI-Manager/blob/main/docs/en/v3.38-userdata-security-migration.md - () https://github.com/Comfy-Org/ComfyUI-Manager/blob/main/docs/en/v3.38-userdata-security-migration.md - Exploit, Third Party Advisory
References () https://github.com/Comfy-Org/ComfyUI-Manager/pull/2338/commits/e44c5cef58fb4973670b86433b9d24d077b44a26 - () https://github.com/Comfy-Org/ComfyUI-Manager/pull/2338/commits/e44c5cef58fb4973670b86433b9d24d077b44a26 - Patch
CPE cpe:2.3:a:comfy:comfyui-manager:*:*:*:*:*:*:*:*

05 Jan 2026, 20:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-420

05 Jan 2026, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-05 16:15

Updated : 2026-01-30 01:31


NVD link : CVE-2025-67303

Mitre link : CVE-2025-67303

CVE.ORG link : CVE-2025-67303


JSON object : View

Products Affected

comfy

  • comfyui-manager
CWE
CWE-420

Unprotected Alternate Channel