Medium severity6.1NVD Advisory· Published Oct 17, 2024· Updated Jun 17, 2026
CVE-2024-10099
CVE-2024-10099
Description
A stored cross-site scripting (XSS) vulnerability exists in comfyanonymous/comfyui version 0.2.2 and possibly earlier. The vulnerability occurs when an attacker uploads an HTML file containing a malicious XSS payload via the /api/upload/image endpoint. The payload is executed when the file is viewed through the /view API endpoint, leading to potential execution of arbitrary JavaScript code.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- comfyanonymous/comfyanonymous/comfyuiv5Range: unspecified
- Range: <=0.2.2
Patches
Vulnerability mechanics
References
1- huntr.com/bounties/14fb8c9a-692a-4d8c-b4b2-24c6f91a383cnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.