{"id":"CVE-2026-22777","aliases":["GHSA-562r-8445-54r2","PYSEC-2026-1260"],"title":"ComfyUI-Manager is Vulnerable to CRLF Injection in Configuration Handler","summary":"ComfyUI-Manager is Vulnerable to CRLF Injection in Configuration Handler","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","vendor":"comfy-cli","product":"comfy-cli","ecosystem":"pip","affected":["comfy-cli >= 4.0.0, < 4.0.5","comfy-cli < 3.39.2"],"patched":["comfy-cli 4.0.5","comfy-cli 3.39.2"],"published":"2026-01-13","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:49:54.341494095Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-562r-8445-54r2","references":[{"url":"https://github.com/Comfy-Org/ComfyUI-Manager/security/advisories/GHSA-562r-8445-54r2"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22777"},{"url":"https://github.com/Comfy-Org/ComfyUI-Manager/commit/ef8703a3d7ab4e6ecda8f96e0c5816c23d1cb262"},{"url":"https://github.com/Comfy-Org/ComfyUI-Manager/commit/f4fa394e0f03b013f1068c96cff168ad10bd0410"},{"url":"https://github.com/Comfy-Org/ComfyUI-Manager"}],"tags":["osv","pip"],"epss":0.00347,"epssPercentile":0.28359,"ingestedAt":"2026-07-08T18:25:45.786Z","slug":"CVE-2026-22777","body":"## Overview\n\n## Impact\n\n**Vulnerability Type**: CRLF Injection via ConfigParser\n\nAn attacker can inject special characters into HTTP query parameters to add arbitrary configuration values to the `config.ini` file. This can lead to security setting tampering or modification of application behavior.\n\n**Affected Users**: Users running ComfyUI-Manager in environments where ComfyUI is configured with the `--listen` option to allow remote access.\n\n**CVSS Score**: 7.5 (High)\n\n## Patches\n\nFixed in the following versions:\n- **3.39.2** (v3.x branch)\n- **4.0.5** (v4.x branch)\n\nSanitization logic was added to the `write_config()` function to remove CRLF and NULL characters from all string values.\n\n## Workarounds\n\nIf upgrading is not possible:\n- Run ComfyUI-Manager only on trusted networks\n- Block external access via firewall\n- Run on localhost only without the `--listen` option\n\n## References\n\n- [CWE-93: Improper Neutralization of CRLF Sequences](https://cwe.mitre.org/data/definitions/93.html)\n- [OWASP CRLF Injection](https://owasp.org/www-community/vulnerabilities/CRLF_Injection)\n\n## Credit\n\nThis vulnerability was reported by:\n- 李存义 <xiaoheihei1107@gmail.com>\n- D0n9 Li <wyd0n9@gmail.com>\n- Swings <swing@mail.exp.sh>\n- Osword from SGLAB of Legendsec at Qi'anxin Group <zhzhdoai@gmail.com>\n\n## Affected packages\n\n- `comfy-cli >= 4.0.0, < 4.0.5`\n- `comfy-cli < 3.39.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `comfy-cli 4.0.5`\n- `comfy-cli 3.39.2`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}