ComfyUI-Bmad-Nodes is vulnerable to Code Injection. The issue stems from...
Vulnerability Description
ComfyUI-Bmad-Nodes is vulnerable to Code Injection. The issue stems from a validation bypass in the BuildColorRangeHSVAdvanced, FilterContour and FindContour custom nodes. In the entrypoint function to each node, there’s a call to eval which can be triggered by generating a workflow that injects a crafted string into the node. This can result in executing arbitrary code on the server.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-21576
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Raul Onitza-Klugman (Snyk Security Research)
Affected Vendor
bmad4ever
View all reports →