PT-2026-2261 · Comfyui · Comfyui-Manager

·

CVE-2026-22777

·

Published

2026-01-10

·

Updated

2026-07-07

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions ComfyUI-Manager versions prior to 3.39.2 ComfyUI-Manager versions prior to 4.0.5
Description ComfyUI-Manager, an extension for ComfyUI, is susceptible to arbitrary configuration injection. An attacker can inject special characters into HTTP query parameters, allowing them to add arbitrary configuration values to the config.ini file. This can result in security setting tampering or modification of application behavior.
Recommendations Update ComfyUI-Manager to version 3.39.2 or later. Update ComfyUI-Manager to version 4.0.5 or later.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-22777
GHSA-562R-8445-54R2
PYSEC-2026-1260

Affected Products

Comfyui-Manager