CVE-2024-21574: Ltdrdata Comfyui-Manager

Critical severity, CVSS 10.0. EPSS: 1.1% chance of exploitation in the next 30 days.

The issue stems from a missing validation of the pip field in a POST request sent to the /customnode/install endpoint used to install custom nodes which is added to the server by the extension. This allows an attacker to craft a request that triggers a pip install on a user controlled package or URL, resulting in remote code execution (RCE) on the server.

Affected products

  • Ltdrdata Comfyui-Manager: before 2.51.1 (fixed in 2.51.1)

Published 2024-12-12. Last modified 2026-06-17.