CVE-2024-21576 - CVE House
Back to Database
Status published Critical CVE-2024-21576

ComfyUI-Bmad-Nodes is vulnerable to Code Injection. The issue stems from...

Vulnerability Description

ComfyUI-Bmad-Nodes is vulnerable to Code Injection. The issue stems from a validation bypass in the BuildColorRangeHSVAdvanced, FilterContour and FindContour custom nodes. In the entrypoint function to each node, there’s a call to eval which can be triggered by generating a workflow that injects a crafted string into the node. This can result in executing arbitrary code on the server.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-21576

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Raul Onitza-Klugman (Snyk Security Research)

Affected Vendor

Affected Software

ComfyUI-Bmad-Nodes
Vulnerable Versions:
0

Timeline

Official Publish: December 13th, 2024
Last Modified: December 23rd, 2024
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)