Comfy Org ComfyUI是Comfy Org组织开源的一款节点式工作流AI绘画工具。 Comfy Org ComfyUI 0.23.0及之前版本存在反序列化注入漏洞,该漏洞源于LoadTrainingDataset节点存在不安全的反序列化问题,攻击者可通过未认证的POST /upload/image端点上传特制pickle文件,并通过POST /prompt触发反序列化,导致以ComfyUI进程用户身份执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-56670 | 8.2 HIGH | ComfyUI: Stored XSS via SVG file upload on the /view endpoint |
| CVE-2026-56672 | 8.2 HIGH | ComfyUI: Stored XSS via /userdata/{file} due to Missing Content-Type Sanitization |
| CVE-2026-56673 | 7.5 HIGH | ComfyUI: Path traversal in LoadImage via the /prompt API allows arbitrary file existence p |
| CVE-2026-56671 | 7.5 HIGH | ComfyUI: Path traversal in /experiment/models/preview allows arbitrary image file read |
No comments yet