An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration and critical data. This was due to the application storing its files in an insufficiently protected location that was accessible via the web interface
References
Configurations
History
30 Jan 2026, 01:31
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Comfy
Comfy comfyui-manager |
|
| References | () https://github.com/Comfy-Org/ComfyUI-Manager/blob/main/docs/en/v3.38-userdata-security-migration.md - Exploit, Third Party Advisory | |
| References | () https://github.com/Comfy-Org/ComfyUI-Manager/pull/2338/commits/e44c5cef58fb4973670b86433b9d24d077b44a26 - Patch | |
| CPE | cpe:2.3:a:comfy:comfyui-manager:*:*:*:*:*:*:*:* |
05 Jan 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| CWE | CWE-420 |
05 Jan 2026, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-05 16:15
Updated : 2026-01-30 01:31
NVD link : CVE-2025-67303
Mitre link : CVE-2025-67303
CVE.ORG link : CVE-2025-67303
JSON object : View
Products Affected
comfy
- comfyui-manager
CWE
CWE-420
Unprotected Alternate Channel
