PatchSiren cyber security CVE debrief
CVE-2026-56673 Comfy-Org CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T06:16:30.520Z and has not been modified since then. ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. The vulnerability allows unauthenticated probing of arbitrary host paths and exfiltration of image-format files through crafted POST /prompt workflows using LoadImage or similar nodes. The issue is fixed in version 0.28.0.
- Vendor
- Comfy-Org
- Product
- ComfyUI
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-31
- Original CVE updated
- 2026-07-31
- Advisory published
- 2026-07-31
- Advisory updated
- 2026-07-31
Who should care
ComfyUI users and administrators, security teams monitoring for potential path probing and file exfiltration attacks, and organizations using affected nodes like LoadImage, LoadImageMask, and LoadVideo. They should verify their systems are updated to version 0.28.0 or later and implement additional logging and monitoring for affected nodes. ComfyUI users should also restrict access to /prompt workflows and /view endpoints to mitigate potential attacks until systems are updated to version 0.28.0 or later. Additionally, they should review compensating controls for exposed systems while remediation is scheduled and verified, and track exceptions, retest remediated assets, and close the item only after evidence is documented. Those responsible for vulnerability management and security teams should prioritize verifying affected scope, severity, and vendor guidance through official advisories or CVE records. They should also plan vendor-supported updates or mitigations through normal change control where exposure is confirmed and review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Furthermore, they should check relevant monitoring, detection, and logs for exposed assets that need extra review and implement additional logging and monitoring for affected nodes to detect potential attacks. Those responsible for asset inventory should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. They should also review compensating controls for exposed systems while remediation is scheduled and verified, and track exceptions, retest remediated assets, and close the item only after evidence is documented. Those responsible for security operations should prioritize monitoring for suspicious LoadImage and sibling node usage and implement additional logging and monitoring for affected nodes to detect potential attacks. They should also review compensating controls for exposed systems while remediation is scheduled and verified, and track exceptions, retest remediated assets, and close the item only after evidence is documented. Those responsible for incident response and
Technical summary
CVE-2026-56673 is a HIGH severity vulnerability in ComfyUI, a modular diffusion model GUI, API, and backend. The issue allows unauthenticated probing of arbitrary host paths and exfiltration of image-format files through crafted POST /prompt workflows using LoadImage or similar nodes. The vulnerability is fixed in version 0.28.0. Affected nodes include LoadImage, LoadImageMask, LoadImageOutput, LoadAudio, LoadLatent, LoadVideo, and Load3D.
Defensive priority
CVE-2026-56673 is rated HIGH with a CVSS score of 7.5. Unaffected scope and vendor remediation status are unknown. ComfyUI users should verify their systems are updated to version 0.28.0 or later.
Recommended defensive actions
- Verify ComfyUI installations are updated to version 0.28.0 or later
- Restrict access to /prompt workflows and /view endpoints
- Monitor for suspicious LoadImage and sibling node usage
- Implement additional logging and monitoring for affected nodes
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
The CVE-2026-56673 issue allows unauthenticated probing of arbitrary host paths and exfiltration of image-format files through crafted POST /prompt workflows using LoadImage or similar nodes in ComfyUI versions before 0.28.0. Evidence is based on official CVE and NVD records, and limited source references.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T06:16:30.520Z and has not been modified since then.