Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

comfyui — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in comfyui, with AI-generated Chinese analysis, references, and POCs.

Vendor: comfyanonymous

CVE ID Title CVSS Severity Published
CVE-2026-92816 ComfyUI before 0.30.0 Path Traversal via dataset save nodes CWE-22 7.8 High 2026-09-16
CVE-2026-68771 ComfyUI 0.23.0 Unauthenticated RCE via LoadTrainingDataset Pickle Deserialization CWE-502 9.8 Critical 2026-07-31
CVE-2026-56673 ComfyUI: Path traversal in LoadImage via the /prompt API allows arbitrary file existence probing and image exfiltration CWE-22 7.5 High 2026-07-31
CVE-2026-56672 ComfyUI: Stored XSS via /userdata/{file} due to Missing Content-Type Sanitization CWE-79 8.2 High 2026-07-31
CVE-2026-56671 ComfyUI: Path traversal in /experiment/models/preview allows arbitrary image file read CWE-22 7.5 High 2026-07-31
CVE-2026-56670 ComfyUI: Stored XSS via SVG file upload on the /view endpoint CWE-79 8.2 High 2026-07-31
CVE-2026-6593 ComfyUI View Endpoint server.py cross site scripting CWE-79 3.5 Low 2026-04-20
CVE-2026-6592 ComfyUI userdata Endpoint user_manager.py getuserdata cross site scripting CWE-79 3.5 Low 2026-04-20
CVE-2026-6591 ComfyUI LoadImage Node folder_paths.py folder_paths.get_annotated_filepath path traversal CWE-22 4.3 Medium 2026-04-20
CVE-2026-6590 ComfyUI Model Preview Endpoint model_manager.py get_model_preview path traversal CWE-22 4.3 Medium 2026-04-20
CVE-2026-6589 ComfyUI server.py create_origin_only_middleware cross-site request forgery CWE-352 4.3 Medium 2026-04-20
CVE-2025-6107 comfyanonymous comfyui utils.py set_attr dynamically-determined object attributes CWE-915 3.1 Low 2025-06-16
CVE-2025-6092 comfyanonymous comfyui Incomplete Fix CVE-2024-10099 image cross site scripting CWE-79 4.3 Medium 2025-06-15

All 13 known CVE vulnerabilities affecting comfyui with full Chinese analysis, references, and POCs where available.