Duty Analyst: Joseph McCarthy

CVE-2025-67303

Published: 2026-01-05 16:15:43 | Last modified: 2026-01-30 01:31:38

HIGH CVSS 7.5
No EPSS data

Description

An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration and critical data. This was due to the application storing its files in an insufficiently protected location that was accessible via the web interface

CVSS details

Severity
high
Score
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

This CVE is not currently listed in the EPSS dataset.

Show JSON
{
    "cve": {
        "id": "CVE-2025-67303",
        "cveTags": [],
        "metrics": {
            "cvssMetricV31": [
                {
                    "type": "Secondary",
                    "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "cvssData": {
                        "scope": "UNCHANGED",
                        "version": "3.1",
                        "baseScore": 7.5,
                        "attackVector": "NETWORK",
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
                        "integrityImpact": "HIGH",
                        "userInteraction": "NONE",
                        "attackComplexity": "LOW",
                        "availabilityImpact": "NONE",
                        "privilegesRequired": "NONE",
                        "confidentialityImpact": "NONE"
                    },
                    "impactScore": 3.6,
                    "exploitabilityScore": 3.9
                }
            ]
        },
        "published": "2026-01-05T16:15:42.977",
        "references": [
            {
                "url": "https://github.com/Comfy-Org/ComfyUI-Manager/blob/main/docs/en/v3.38-userdata-security-migration.md",
                "tags": [
                    "Exploit",
                    "Third Party Advisory"
                ],
                "source": "cve@mitre.org"
            },
            {
                "url": "https://github.com/Comfy-Org/ComfyUI-Manager/pull/2338/commits/e44c5cef58fb4973670b86433b9d24d077b44a26",
                "tags": [
                    "Patch"
                ],
                "source": "cve@mitre.org"
            }
        ],
        "vulnStatus": "Analyzed",
        "weaknesses": [
            {
                "type": "Secondary",
                "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                "description": [
                    {
                        "lang": "en",
                        "value": "CWE-420"
                    }
                ]
            }
        ],
        "descriptions": [
            {
                "lang": "en",
                "value": "An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration and critical data. This was due to the application storing its files in an insufficiently protected location that was accessible via the web interface"
            }
        ],
        "lastModified": "2026-01-30T01:31:37.653",
        "configurations": [
            {
                "nodes": [
                    {
                        "negate": false,
                        "cpeMatch": [
                            {
                                "criteria": "cpe:2.3:a:comfy:comfyui-manager:*:*:*:*:*:*:*:*",
                                "vulnerable": true,
                                "matchCriteriaId": "A2BEDC7B-32BB-4C47-81B5-4EC4357B3E36",
                                "versionEndExcluding": "3.38"
                            }
                        ],
                        "operator": "OR"
                    }
                ]
            }
        ],
        "sourceIdentifier": "cve@mitre.org"
    }
}