[security] class pollution vulnerability#8435
[security] class pollution vulnerability#8435superboy-zjc wants to merge 1 commit intoComfy-Org:masterfrom
Conversation
|
Looks good, I will raise this to the team later today to try to get it merged quickly. |
|
HI @Kosinkadink Could the team also acknowledge the vulnerability report I sent via the security page? Thx! |
|
And can you please not report minor bugs as major security vulns. Bugs like this should be reported as a normal issue. |
Thanks for your response, but I think there’s a misunderstanding here.
We’re happy to discuss the details, but we also expect basic courtesy. Open-source thrives on collaboration, not shutting people down |
fix the security issue reported at: https://github.com/comfyanonymous/ComfyUI/security/advisories/GHSA-88r9-f379-rhhg