CVE-2024-10481: Cross-Site Request Forgery (CSRF) in comfyanonymous/comfyui

Published Mar 20, 2025
·
Updated

A CSRF vulnerability exists in comfyanonymous/comfyui versions up to v0.2.2. This vulnerability allows attackers to host malicious websites that, when visited by authenticated ComfyUI users, can perform arbitrary API requests on behalf of the user. This can be exploited to perform actions such as uploading arbitrary files via the /upload/image endpoint. The lack of CSRF protections on API endpoints like /upload/image, /prompt, and /history leaves users vulnerable to unauthorized actions, which could be combined with other vulnerabilities such as stored-XSS to further compromise user sessions.

Affected Software

2 affected components
comfyanonymous comfyui<0.2.2
Comfy comfyui<=0.2.2

Event History

Mar 20, 2025
CVE Published
via MITRE·10:09 AM
Data Sourced
via MITRE·10:09 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-10481?

CVE-2024-10481 has been categorized as a moderate severity CSRF vulnerability affecting ComfyUI.

2

How do I fix CVE-2024-10481?

To fix CVE-2024-10481, upgrade ComfyUI to version 0.2.3 or later.

3

What versions are affected by CVE-2024-10481?

CVE-2024-10481 affects ComfyUI versions up to and including v0.2.2.

4

What type of attack does CVE-2024-10481 enable?

CVE-2024-10481 enables attackers to perform arbitrary API requests on behalf of authenticated ComfyUI users via CSRF.

5

Who is impacted by CVE-2024-10481?

Users of ComfyUI versions up to v0.2.2 are at risk of being exploited by CVE-2024-10481.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203