← Back to browse · API

CVE-2024-21577

Severity
CRITICAL
CVSS
10.0
EPSS
0.00571
Risk score
40.2
CISA KEV
No
PoC
No
Published
2024-12-13
Modified
2024-12-23
First seen
2026-08-07
Aliases
EUVD-2024-19226, GHSA-RJX4-8GXJ-W5GJ
Products
hay86:ComfyUI-Ace-Nodes 0 <*
Sources
euvd EUVD-2024-19226

Description

ComfyUI-Ace-Nodes is vulnerable to Code Injection. The ACE_ExpressionEval node contains an eval() in its entrypoint function that accepts arbitrary user-controlled data. A user can create a workflow that results in executing arbitrary code on the server.

References