First published: Tue Oct 29 2024(Updated: )
A Cross-Site Request Forgery (CSRF) vulnerability exists in the `install_comfyui` endpoint of the `lollms_comfyui.py` file in the parisneo/lollms-webui repository, versions v9.9 to the latest. The endpoint uses the GET method without requiring a client ID, allowing an attacker to trick a victim into installing ComfyUI. If the victim's device does not have sufficient capacity, this can result in a crash.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Lollms Lollms Web Ui | <10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.