ComfyUI 是一个基于图形和节点接口的模块化扩散模型 GUI、API 和后端。在 0.28.0 版本之前, 和 函数将工作流控制的注解文件名与基础目录连接时,未进行目录包含检查,导致未经身份验证的攻击者可以通过构造的 POST /prompt 请求,利用 LoadImage 或相关节点探测任意主机路径,并通过 /view 接口泄露图像格式文件。LoadImage 定义了 方法,导致执行引擎跳过了 COMBO(输入目录)类型的验证。受影响的节点包括:LoadImage、LoadImageMask、LoadImag
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-68771 | 9.8 CRITICAL | ComfyUI 0.23.0 Unauthenticated RCE via LoadTrainingDataset Pickle Deserialization |
| CVE-2026-56670 | 8.2 HIGH | ComfyUI: Stored XSS via SVG file upload on the /view endpoint |
| CVE-2026-56672 | 8.2 HIGH | ComfyUI: Stored XSS via /userdata/{file} due to Missing Content-Type Sanitization |
| CVE-2026-56671 | 7.5 HIGH | ComfyUI: Path traversal in /experiment/models/preview allows arbitrary image file read |
No comments yet