PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-13493 AIDC-AI CVE debrief

CVE-2026-13493 is a vulnerability in AIDC-AI ComfyUI-Copilot up to version 2.0.28. The issue affects the Workflow Checkpoint Restore Handler in the file backend/controller/conversation_api.py. This vulnerability allows for improper control of resource identifiers, which can be exploited remotely. The complexity level of this attack is high and its exploitability is assessed as difficult. The exploit has been published and may be used by attackers. A pull request to fix this issue has been submitted but has not yet been accepted.

Vendor
AIDC-AI
Product
ComfyUI-Copilot
CVSS
LOW 1.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-28
Original CVE updated
2026-06-28
Advisory published
2026-06-28
Advisory updated
2026-06-28

Who should care

Defenders of AIDC-AI ComfyUI-Copilot installations should be aware of this vulnerability. Given the remote exploitability and publication of the exploit, defenders should prioritize patching. This vulnerability has a low CVSS score of 1.3, indicating a low severity, but defenders should still take action to secure their systems.

Technical summary

The vulnerability in AIDC-AI ComfyUI-Copilot up to 2.0.28 is located in the Workflow Checkpoint Restore Handler within the file backend/controller/conversation_api.py. It allows for improper control of resource identifiers. The attack vector is network-based, and the attack complexity is high, making it difficult to exploit. The CVSS vector is CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X.

Defensive priority

Defenders should prioritize patching CVE-2026-13493. Although the CVSS severity is low, the exploit has been published, increasing the risk of exploitation.

Recommended defensive actions

  • Apply the patch from the pull request once it is accepted.
  • Restrict access to the Workflow Checkpoint Restore Handler.
  • Monitor for suspicious activity related to the Workflow Checkpoint Restore Handler.
  • Ensure that the system is up to date with the latest security patches.
  • Consider implementing compensating controls to mitigate the risk of exploitation.

Evidence notes

The CVE-2026-13493 entry was created on June 28, 2026, and has not been modified since. The vulnerability was discovered in AIDC-AI ComfyUI-Copilot up to version 2.0.28. The exploit has been published, and a pull request for a fix has been submitted. The CVSS score is 1.3, indicating a low severity.

Official resources

This article is AI-assisted and based on the supplied source corpus.