python313-comfyui-frontend-package-1.52.7-1.1 on GA media
Description
These are all security issues fixed in the python313-comfyui-frontend-package-1.52.7-1.1 package on the GA media of openSUSE Tumbleweed.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-65898 is a cross-site scripting vulnerability in DOMPurify, a library used in Red Hat Hardened Images RPMs, specifically affecting grafana12.4 packages. The vulnerability arises because the ALLOWED_ATTR allowlist is not properly cloned when the setConfig() function is used with an uponSanitizeAttribute hook. This allows an attacker to permanently mutate the shared allowlist, enabling conditional allowance of dangerous attributes. Consequently, untrusted content can inherit the polluted allowlist, leading to stored XSS and execution of event handlers. Red Hat has published an advisory detailing this issue and the affected packages but currently does not offer a remediation that meets their standards.
Potential Impact
The vulnerability allows attackers to perform stored cross-site scripting attacks by injecting malicious attributes that are conditionally allowed due to the polluted allowlist. This can lead to execution of unauthorized scripts in the context of users visiting affected applications, potentially compromising confidentiality and integrity by stealing cookies, session tokens, or executing arbitrary code in the victim's browser. The impact is rated medium by Red Hat, reflecting the potential for unauthorized code execution and data exposure via XSS.
Mitigation Recommendations
Red Hat currently does not provide an official fix or mitigation that meets their criteria for ease of deployment and applicability. Users should monitor Red Hat advisories for updates. Until a fix is available, consider restricting the use of the setConfig() function with uponSanitizeAttribute hooks in DOMPurify or applying application-level controls to sanitize inputs and outputs. Follow Red Hat's guidance at https://images.redhat.com/ for updates and instructions.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:58500
- Cve Count
- 8
- Additional Cves
- ["CVE-2026-65899","CVE-2026-65901","CVE-2026-65902","CVE-2026-65911","CVE-2026-65912","CVE-2026-65913","CVE-2026-65914"]
- State
- PUBLISHED
Threat ID: 6a8a27fdacd9273b499bca97
Added to database: 08/22/2026, 22:51:41 UTC
Last enriched: 09/10/2026, 23:48:12 UTC
Last updated: 10/06/2026, 18:48:24 UTC
Views: 83
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.