CVE-2024-21574: Ltdrdata Comfyui-Manager
Critical severity, CVSS 10.0. EPSS: 1.1% chance of exploitation in the next 30 days.
The issue stems from a missing validation of the pip field in a POST request sent to the /customnode/install endpoint used to install custom nodes which is added to the server by the extension. This allows an attacker to craft a request that triggers a pip install on a user controlled package or URL, resulting in remote code execution (RCE) on the server.
Affected products
- Ltdrdata Comfyui-Manager: before 2.51.1 (fixed in 2.51.1)
Published 2024-12-12. Last modified 2026-06-17.