Browse all 5 CVE security advisories affecting comfyanonymous. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Comfyanonymous develops security-focused software with a core use case in providing privacy-preserving communication tools. Historically, the project has been associated with vulnerabilities including remote code execution, cross-site scripting, and privilege escalation issues. The software has demonstrated security characteristics emphasizing anonymity but has faced incidents where improper input validation led to exploitable flaws. With five CVEs on record, these vulnerabilities typically stem from insufficient sanitization of user inputs and insecure default configurations. The project's security posture reflects ongoing challenges in balancing functionality with robust protection against common web application threats while maintaining its core privacy objectives.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-6107 | comfyanonymous comfyui utils.py set_attr dynamically-determined object attributes — comfyuiCWE-915 | 3.1 | Low | 2025-06-16 |
| CVE-2025-6092 | comfyanonymous comfyui Incomplete Fix CVE-2024-10099 image cross site scripting — comfyuiCWE-79 | 4.3 | Medium | 2025-06-15 |
This page lists every published CVE security advisory associated with comfyanonymous. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.