CVE-2025-6107: comfyanonymous comfyui utils.py set_attr dynamically-determined object attributes
A vulnerability was found in comfyanonymous comfyui 0.3.40. It has been classified as problematic. Affected is the function setattr of the file /comfy/utils.py. The manipulation leads to dynamically-determined object attributes. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6107?
CVE-2025-6107 has been classified as problematic, indicating significant security concerns.
How do I fix CVE-2025-6107?
To fix CVE-2025-6107, review and update the function set_attr in /comfy/utils.py to prevent security vulnerabilities.
What are the potential impacts of CVE-2025-6107?
CVE-2025-6107 could allow an attacker to manipulate dynamically-determined object attributes, leading to remote exploitation.
Which software is affected by CVE-2025-6107?
The vulnerable software is comfyanonymous comfyui version 0.3.40.
Can CVE-2025-6107 be exploited remotely?
Yes, CVE-2025-6107 can be exploited remotely, making it critical to address promptly.