CVE-2024-12952

CVSS 2.0 Score 6.5 of 10 (medium)

Details

Published Dec 26, 2024
CWE ID 94
CWE ID 74

Summary

CVE-2024-12952 is a newly disclosed critical vulnerability that affects melMass comfy_mtb up to version 0.1.4. The issue lies in the function run_command of comfy_mtb/endpoint.py within the Dependency Handler component. An attacker can exploit this flaw to inject code remotely, resulting in potentially serious consequences. The exploit has been made public, increasing the risk of attacks. To mitigate this vulnerability, it is strongly advised to apply the patch with the commit hash d6e004cce2c32f8e48b868e66b89f82da4887dc3.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share