ComfyUI 是一个模块化的扩散模型图形用户界面(GUI)、API 和后端,采用图/节点式界面设计。在版本 0.28.0 之前, 中的 函数将一个不受限制的文件名路由捕获结果直接拼接到用户选择的模型目录中,且未进行目录包含性检查(containment check)。这导致未认证的远程攻击者可以通过路径遍历、编码后的路径遍历、绝对路径或无限制的 参数,读取可被图像解码的文件,并枚举主机上的路径信息。 具体来说, (位于 )使用 构建路径,其中 是一个不受限制的路由捕获参数 。攻击者可通过 literal 形式的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-68771 | 9.8 CRITICAL | ComfyUI 0.23.0 Unauthenticated RCE via LoadTrainingDataset Pickle Deserialization |
| CVE-2026-56670 | 8.2 HIGH | ComfyUI: Stored XSS via SVG file upload on the /view endpoint |
| CVE-2026-56672 | 8.2 HIGH | ComfyUI: Stored XSS via /userdata/{file} due to Missing Content-Type Sanitization |
| CVE-2026-56673 | 7.5 HIGH | ComfyUI: Path traversal in LoadImage via the /prompt API allows arbitrary file existence p |
No comments yet