Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6975 | comfyanonymous/comfyui version v0.2.4 suffers from a non-blind Server-Side Request Forgery (SSRF) vulnerability. This vulnerability can be exploited by combining the REST APIs `POST /internal/models/download` and `GET /view`, allowing attackers to abuse the victim server's credentials to access unauthorized web resources. |
Fri, 01 Aug 2025 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Comfy
Comfy comfyui |
|
| CPEs | cpe:2.3:a:comfy:comfyui:0.2.4:*:*:*:*:*:*:* | |
| Vendors & Products |
Comfy
Comfy comfyui |
Thu, 20 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | comfyanonymous/comfyui version v0.2.4 suffers from a non-blind Server-Side Request Forgery (SSRF) vulnerability. This vulnerability can be exploited by combining the REST APIs `POST /internal/models/download` and `GET /view`, allowing attackers to abuse the victim server's credentials to access unauthorized web resources. | |
| Title | SSRF in comfyanonymous/comfyui | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-03-20T18:20:26.580Z
Reserved: 2024-12-20T22:14:49.438Z
Link: CVE-2024-12882
Updated: 2025-03-20T17:51:22.250Z
Status : Analyzed
Published: 2025-03-20T10:15:31.593
Modified: 2025-08-01T01:18:23.780
Link: CVE-2024-12882
No data.
OpenCVE Enrichment
No data.
EUVD