ComfyUI-Manager < 3.38 contains an insecure file storage vulnerability caused by storing files in an insufficiently protected location accessible via the web interface, letting remote attackers manipulate configuration and critical data, exploit requires web access.
id: CVE-2025-67303
info:
name: ComfyUI-Manager < 3.38 - Configuration Overwrite
author: maciejk
...