PatchSiren

Comfy-Org CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Comfy-Org CVE published 2026-07-31

CVE-2026-56672

CVE-2026-56672 is a stored cross-site scripting vulnerability in ComfyUI's GET /userdata/{file} endpoint. Prior to version 0.28.0, user-controlled HTML and SVG files were served with extension-derived content types, allowing scripts to execute same-origin and access sensitive information. This issue allows attackers to access browser-stored API tokens, settings, workflows, and make authenticated-equivalen [truncated]