All 7 CVE vulnerabilities found in comfyui, with AI-generated Chinese analysis, references, and POCs.
Vendor: comfyanonymous
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-6593 | ComfyUI View Endpoint server.py cross site scripting CWE-79 | 3.5 | Low | 2026-04-20 |
| CVE-2026-6592 | ComfyUI userdata Endpoint user_manager.py getuserdata cross site scripting CWE-79 | 3.5 | Low | 2026-04-20 |
| CVE-2026-6591 | ComfyUI LoadImage Node folder_paths.py folder_paths.get_annotated_filepath path traversal CWE-22 | 4.3 | Medium | 2026-04-20 |
| CVE-2026-6590 | ComfyUI Model Preview Endpoint model_manager.py get_model_preview path traversal CWE-22 | 4.3 | Medium | 2026-04-20 |
| CVE-2026-6589 | ComfyUI server.py create_origin_only_middleware cross-site request forgery CWE-352 | 4.3 | Medium | 2026-04-20 |
| CVE-2025-6107 | comfyanonymous comfyui utils.py set_attr dynamically-determined object attributes CWE-915 | 3.1 | Low | 2025-06-16 |
| CVE-2025-6092 | comfyanonymous comfyui Incomplete Fix CVE-2024-10099 image cross site scripting CWE-79 | 4.3 | Medium | 2025-06-15 |
All 7 known CVE vulnerabilities affecting comfyui with full Chinese analysis, references, and POCs where available.