HIGH
Comfy-Org
CVE published 2026-07-31
CVE-2026-56672
CVE-2026-56672 is a stored cross-site scripting vulnerability in ComfyUI's GET /userdata/{file} endpoint. Prior to version 0.28.0, user-controlled HTML and SVG files were served with extension-derived content types, allowing scripts to execute same-origin and access sensitive information. This issue allows attackers to access browser-stored API tokens, settings, workflows, and make authenticated-equivalen [truncated]