We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
A Cross-Site Request Forgery (CSRF) vulnerability exists in the `install_comfyui` endpoint of the `lollms_comfyui.py` file in the parisneo/lollms-webui repository, versions v9.9 to the latest. The endpoint uses the GET method without requiring a client ID, allowing an attacker to trick a victim into installing ComfyUI. If the victim's device does not have sufficient capacity, this can result in a crash.
Reserved 2024-07-10 | Published 2024-10-29 | Updated 2024-10-29 | Assigner @huntr_aiCWE-352 Cross-Site Request Forgery (CSRF)
huntr.com/bounties/a38f9a7d-b357-427d-adac-f9654d8c0e3c
github.com/...ommit/c1bb1ad19752aa7541675b398495eaf98fd589f1
Support options