wgpsec/aboutsecurity

comfyui-exploit

ComfyUI-Manager 漏洞利用技能,涵盖两个CVE的完整攻击链: CVE-2025-67303(配置文件未授权读写导致RCE)和 CVE-2026-22777(CRLF注入降级安全级别导致RCE)。 两者最终都通过安装恶意自定义节点实现远程代码执行。 当用户提到…

First seen Apr 22, 2026

Installation

$ npx skills add https://github.com/wgpsec/aboutsecurity

Summary

ComfyUI-Manager 漏洞利用技能,涵盖两个CVE的完整攻击链: CVE-2025-67303(配置文件未授权读写导致RCE)和 CVE-2026-22777(CRLF注入降级安全级别导致RCE)。 两者最终都通过安装恶意自定义节点实现远程代码执行。 当用户提到…

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from wgpsec/aboutsecurity · top by installs.

npx skills add https://github.com/wgpsec/aboutsecurity

Browse all from wgpsec/aboutsecurity

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 1.7K
Default branch master
Open issues 0
Status Active

History

  1. First seen on skills.sh
  2. First recorded snapshot · 1 installs