Comfyanonymous Comfyui Server-Side Request Forgery Vulnerability

Vulnerability

A non-blind Server-Side Request Forgery (SSRF) vulnerability has been identified in Comfyanonymous Comfyui version v0.2.4. This vulnerability arises from the improper handling of the 'url' parameter in the 'POST /internal/models/download' API, which can be exploited to access unauthorized web resources using the victim server's credentials.

Impact

Exploitation of this vulnerability allows attackers to use the victim server's credentials to access restricted web resources.

Reproduction

To reproduce this vulnerability, first upload a file named 'secret.safetensors' to the 'checkpoints' directory of the ComfyUI installation. Then, send a POST request to '/internal/models/download' with the URL of the uploaded file, the model directory, and the correct folder path. After successfully downloading the file, send a GET request to '/view' with the subfolder and filename parameters to access the contents of the downloaded file, which will include the data from the original URL.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.8
exploitability
8.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.