Skip to main content
EPSS 0.3%top 79%

python313-comfyui-frontend-package-1.52.7-1.1 on GA media

0
Medium
Published: 09/08/2026 (09/08/2026, 00:00:00 UTC)
Source: GCVE Database
Vendor/Project: SUSE Product Security Team
Product: SUSE

Description

These are all security issues fixed in the python313-comfyui-frontend-package-1.52.7-1.1 package on the GA media of openSUSE Tumbleweed.

Affected software

Affected versions
>=12.4.0 <=12.4.7SUSEaarch64python313-comfyui-frontend-package-1.52.7-1.1.aarch64python314-comfyui-frontend-package-1.52.7-1.1.aarch64ppc64le

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 23:48:12 UTC

Technical Analysis

CVE-2026-65898 is a cross-site scripting vulnerability in DOMPurify, a library used in Red Hat Hardened Images RPMs, specifically affecting grafana12.4 packages. The vulnerability arises because the ALLOWED_ATTR allowlist is not properly cloned when the setConfig() function is used with an uponSanitizeAttribute hook. This allows an attacker to permanently mutate the shared allowlist, enabling conditional allowance of dangerous attributes. Consequently, untrusted content can inherit the polluted allowlist, leading to stored XSS and execution of event handlers. Red Hat has published an advisory detailing this issue and the affected packages but currently does not offer a remediation that meets their standards.

Potential Impact

The vulnerability allows attackers to perform stored cross-site scripting attacks by injecting malicious attributes that are conditionally allowed due to the polluted allowlist. This can lead to execution of unauthorized scripts in the context of users visiting affected applications, potentially compromising confidentiality and integrity by stealing cookies, session tokens, or executing arbitrary code in the victim's browser. The impact is rated medium by Red Hat, reflecting the potential for unauthorized code execution and data exposure via XSS.

Mitigation Recommendations

Red Hat currently does not provide an official fix or mitigation that meets their criteria for ease of deployment and applicability. Users should monitor Red Hat advisories for updates. Until a fix is available, consider restricting the use of the setConfig() function with uponSanitizeAttribute hooks in DOMPurify or applying application-level controls to sanitize inputs and outputs. Follow Red Hat's guidance at https://images.redhat.com/ for updates and instructions.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:58500
Cve Count
8
Additional Cves
["CVE-2026-65899","CVE-2026-65901","CVE-2026-65902","CVE-2026-65911","CVE-2026-65912","CVE-2026-65913","CVE-2026-65914"]
State
PUBLISHED

Threat ID: 6a8a27fdacd9273b499bca97

Added to database: 08/22/2026, 22:51:41 UTC

Last enriched: 09/10/2026, 23:48:12 UTC

Last updated: 10/06/2026, 18:48:24 UTC

Views: 83

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses