An Unprotected Alternate Channel (CWE-420) vulnerability was discovered in ComfyUI-Manager versions prior to 3.38.
In affected versions, ComfyUI-Manager stored its configuration in the user/default/ComfyUI-Manager/ directory, which was accessible via ComfyUI's web APIs without proper access control. This unprotected alternate channel allowed remote attackers to read and manipulate configuration files and critical data through the web interface.
An attacker exploiting this vulnerability could:
| Configuration | Risk Level |
|---------------|------------|
| Systems running with --listen 0.0.0.0 (externally exposed) | HIGH |
| Systems behind reverse proxy without proper access control | MEDIUM |
| Local-only installations (default, localhost only) | NOT AFFECTED |
This issue has been patched in ComfyUI-Manager version 3.38.
| Component | Minimum Version | Notes | |-----------|-----------------|-------| | ComfyUI | v0.3.76+ | Required for System User Protection API | | ComfyUI-Manager | v3.38+ | Contains the security fix |
user/default/ComfyUI-Manager/ to protected user/__manager/__manager/ directory leverages ComfyUI's System User Protection API, which blocks external web API access3.38Exploitability
AV:NAC:LPR:NUI:NScope
S:UImpact
C:NI:HA:NCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N