CVE-2025-67303 is an unprotected alternate-channel vulnerability in ComfyUI-Manager versions earlier than 3.38. Configuration files are stored in a web-accessible location and can be accessed through ComfyUI web APIs without authorization. An attacker can read configuration data and overwrite configuration values, including lowering the security level, which bypasses security controls and may enable remote code execution through subsequent manager behavior.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (5 hidden).
This four-file repository implements an operational network RCE chain against claimed vulnerable ComfyUI-Manager releases. autopwn.py is the primary all-in-one Python exploit: it creates a bare Git repository containing a malicious install.py, hosts it with Python's HTTP server, injects a carriage return into the db_mode configuration value to forge security_level=weak, requests a Manager reboot, polls the Git-install endpoint for a 403-to-400 transition, and submits the hosted repository URL. It can generate either a configurable Python/Bash reverse shell or a blind command payload. exploit.sh implements the same phased chain with curl and expects setup_evil_repo.sh to create and serve the malicious repository on TCP/9099. The latter builds a plausible custom-node repository and embeds a Python socket reverse shell. README.md documents the claimed CVEs, affected versions, setup, validation behavior, and mitigations. A documentation inconsistency refers to exploit_ad15.sh, while the supplied repository contains exploit.sh instead.
The repository contains two Python files: a minimal ComfyUI custom-node initializer and a malicious 3 KB install.py entry point. The installer searches upward from the current directory for a ComfyUI root by identifying custom_nodes and user directories. It then executes a shell script to identify the effective user, enumerate directories, search likely flag paths, dump all environment variables (with a separate secret-focused filter), and locate files named like flags. Collected output is written under predictable ComfyUI user/default paths, the current directory, and /tmp using the filename zz_67303_gh.txt. Finally, it makes best-effort HTTP POST callbacks containing the collected data to four hard-coded private-network listener URLs. This is an operational malicious installer/supply-chain payload rather than a vulnerability-specific PoC; it has no CVE targeting and no benign ComfyUI node implementation.
Repository purpose: a proof-of-concept malicious ComfyUI custom node intended to demonstrate RCE via ComfyUI-Manager custom node installation (README references CVE-2025-67303 and a Doyensec advisory PDF). Structure and key files: - README.md: minimal description and link to Doyensec advisory. - __init__.py: defines a ComfyUI PromptServer route GET /poc. It reads the 'cmd' query parameter and executes it with subprocess.run(..., shell=True), returning stdout in the HTTP response. This is a direct unauthenticated command-execution backdoor if the route is reachable. - custom-node-list.json: metadata describing a custom node titled "RCE" with install_type "git-clone" pointing to this GitHub repo, consistent with ComfyUI-Manager’s custom node distribution mechanism. - install.py: code executed during installation (if the manager runs it). It prints an exploit banner (note: it mentions CVE-2025-45076, which is inconsistent with the README/CVE name) and attempts to spawn a netcat listener on TCP/4444. On Linux it uses `nc -lvnp 4444 -e /bin/bash` (bind shell behavior if supported by the nc variant). On macOS/Windows it starts a basic listener without `-e`. Overall capabilities: - Network-accessible RCE via the /poc HTTP endpoint executing arbitrary shell commands. - Installer-time code execution that attempts to open a listener on port 4444, potentially providing a shell on Linux depending on netcat implementation. Notable observations: - The CVE referenced in install.py (CVE-2025-45076) appears to be a typo/mismatch relative to the repository name/README (CVE-2025-67303).
Repository contains a malicious ComfyUI custom node disguised as an "AI Enhancement" plugin. Structure: - node.py: Defines a ComfyUI node ("Fake AI Enhancement"). When the node's process() method is invoked, it executes the contents of __init__.py via exec(open("__init__.py").read()), providing arbitrary code execution in the ComfyUI runtime. - __init__.py: Implements the actual payload and prints activation messages referencing "ComfyUI-Manager CVE-2025-67303". Payload actions include: (1) spawning a bash reverse shell to 127.0.0.1:9000, (2) dropping a PHP webshell to /tmp/webshell.php, and (3) writing basic host reconnaissance data to /tmp/target_<hostname>.txt. - pyproject.toml: Packaging/metadata to appear legitimate ("Advanced AI enhancement for ComfyUI"). Overall purpose: a supply-chain style malicious plugin that triggers on node execution to run attacker-controlled actions (shell access + persistence via dropped webshell + recon).
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability in ComfyUI-Manager versions prior to 3.38 that allows configuration overwrite, causing a security bypass that can lead to remote code execution.
A vulnerability identified as a configuration data extraction issue in ComfyUI-Manager.
A critical information disclosure/config data exposure issue in ComfyUI-Manager versions prior to v3.38 where configuration files are stored in an unprotected, web-accessible location, enabling unauthenticated access to sensitive security settings and channel configuration data.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.