PatchSiren cyber security CVE debrief
CVE-2026-13493 AIDC-AI CVE debrief
CVE-2026-13493 is a vulnerability in AIDC-AI ComfyUI-Copilot up to version 2.0.28. The issue affects the Workflow Checkpoint Restore Handler in the file backend/controller/conversation_api.py. This vulnerability allows for improper control of resource identifiers, which can be exploited remotely. The complexity level of this attack is high and its exploitability is assessed as difficult. The exploit has been published and may be used by attackers. A pull request to fix this issue has been submitted but has not yet been accepted.
- Vendor
- AIDC-AI
- Product
- ComfyUI-Copilot
- CVSS
- LOW 1.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-28
- Original CVE updated
- 2026-06-28
- Advisory published
- 2026-06-28
- Advisory updated
- 2026-06-28
Who should care
Defenders of AIDC-AI ComfyUI-Copilot installations should be aware of this vulnerability. Given the remote exploitability and publication of the exploit, defenders should prioritize patching. This vulnerability has a low CVSS score of 1.3, indicating a low severity, but defenders should still take action to secure their systems.
Technical summary
The vulnerability in AIDC-AI ComfyUI-Copilot up to 2.0.28 is located in the Workflow Checkpoint Restore Handler within the file backend/controller/conversation_api.py. It allows for improper control of resource identifiers. The attack vector is network-based, and the attack complexity is high, making it difficult to exploit. The CVSS vector is CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X.
Defensive priority
Defenders should prioritize patching CVE-2026-13493. Although the CVSS severity is low, the exploit has been published, increasing the risk of exploitation.
Recommended defensive actions
- Apply the patch from the pull request once it is accepted.
- Restrict access to the Workflow Checkpoint Restore Handler.
- Monitor for suspicious activity related to the Workflow Checkpoint Restore Handler.
- Ensure that the system is up to date with the latest security patches.
- Consider implementing compensating controls to mitigate the risk of exploitation.
Evidence notes
The CVE-2026-13493 entry was created on June 28, 2026, and has not been modified since. The vulnerability was discovered in AIDC-AI ComfyUI-Copilot up to version 2.0.28. The exploit has been published, and a pull request for a fix has been submitted. The CVSS score is 1.3, indicating a low severity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-13493 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-13493
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-13493 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-13493
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/AIDC-AI/ComfyUI-Copilot/
-
Source reference
Unverified legacy reference
URL: https://github.com/AIDC-AI/ComfyUI-Copilot/issues/149
-
Source reference
Unverified legacy reference
URL: https://github.com/AIDC-AI/ComfyUI-Copilot/pull/150
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-13493
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/838497
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/374489
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/374489/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.