Comfy
Security Risk Profile
37
/100
lowSecurity Risk Score
Comprehensive risk assessment based on 5 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from October 17, 2024 to present
5
Total CVEs
3
Critical+High
0
Exploited
1
Unpatched
Threat Assessment
Avg CVSS
7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
1
Critical/High
Risk Level
37/100
low
Severity Distribution
Critical
0High
3Medium
2Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
1Age Distribution
Common Weaknesses (CWE)
1
XSS
2
2
CRLF Injection
1
3
SSRF
1
4
CSRF
1
Most Affected Products
1. Comfy ComfyUI-Manager3
2. Comfy comfyui3
3. pip/comfy-cli2
4. comfyanonymous comfyui2
5. ComfyUI ComfyUI-Manager1
Recent Vulnerabilities
See more →CVE-2026-22777
CVSS 7.5EPSS 0%high
ComfyUI-Manager is Vulnerable to CRLF Injection in Configuration Handler
1/10/2026
CVE-2025-67303
CVSS 7.5high
1/5/2026
CVE-2024-12882
CVSS 7.5high
SSRF in comfyanonymous/comfyui
3/20/2025🔧 No Patch
CVE-2024-10481
CVSS 6.5medium
Cross-Site Request Forgery (CSRF) in comfyanonymous/comfyui
3/20/2025🔧 No Patch
CVE-2024-10099
CVSS 6.1medium
Stored XSS in comfyanonymous/comfyui
10/17/2024🔧 No Patch
Monitor Comfy in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.