ComfyUI v0.23.0 contains a critical vulnerability due to unsafe deserialization in the LoadTrainingDataset node, allowing unauthenticated remote attackers to execute arbitrary Python code. The vulnerability is exploited by uploading a crafted pickle file via the POST /upload/image endpoint and queuing a workflow graph via POST /prompt. This results in the deserialization of the malicious pickle payload, l [truncated]
CVE-2026-56673 is a high-severity vulnerability in ComfyUI, a modular diffusion model GUI, API, and backend. The issue allows unauthenticated attackers to probe arbitrary host paths and exfiltrate image-format files through crafted POST /prompt workflows. Affected nodes include LoadImage, LoadImageMask, LoadImageOutput, LoadAudio, LoadLatent, LoadVideo, and Load3D. This issue is fixed in version 0.28.0. D [truncated]
CVE-2026-56672 is a stored cross-site scripting vulnerability in ComfyUI's GET /userdata/{file} endpoint. Prior to version 0.28.0, user-controlled HTML and SVG files were served with extension-derived content types, allowing scripts to execute same-origin and access sensitive information. This issue allows attackers to access browser-stored API tokens, settings, workflows, and make authenticated-equivalen [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T06:16:27.560Z and has not been modified since then. CVE-2026-56670 is a HIGH severity vulnerability in ComfyUI, a modular diffusion model GUI, api and backend. The /view endpoint served uploaded SVG files inline due to missing dangerous-content-type handling for image/svg+xml and related XML cont [truncated]