ComfyUI 是一个采用图形/节点接口的模块化扩散模型图形用户界面、API 和后端系统。在版本 0.28.0 之前,/view 端点会以内联方式提供上传的 SVG 文件,因为系统在处理危险内容类型时未包含 image/svg+xml 及相关 XML 内容类型,从而导致在 ComfyUI 源域中存在存储型跨站脚本(XSS)漏洞。该问题已在 0.28.0 版本中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-68771 | 9.8 CRITICAL | ComfyUI 0.23.0 Unauthenticated RCE via LoadTrainingDataset Pickle Deserialization |
| CVE-2026-56672 | 8.2 HIGH | ComfyUI: Stored XSS via /userdata/{file} due to Missing Content-Type Sanitization |
| CVE-2026-56673 | 7.5 HIGH | ComfyUI: Path traversal in LoadImage via the /prompt API allows arbitrary file existence p |
| CVE-2026-56671 | 7.5 HIGH | ComfyUI: Path traversal in /experiment/models/preview allows arbitrary image file read |
No comments yet