Browse all 6 CVE security advisories affecting Comfy-Org. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-68771 | ComfyUI 0.23.0 Unauthenticated RCE via LoadTrainingDataset Pickle Deserialization — ComfyUICWE-502 | 9.8 | Critical | 2026-07-31 |
| CVE-2026-56673 | ComfyUI: Path traversal in LoadImage via the /prompt API allows arbitrary file existence probing and image exfiltration — ComfyUICWE-22 | 7.5 | High | 2026-07-31 |
| CVE-2026-56672 | ComfyUI: Stored XSS via /userdata/{file} due to Missing Content-Type Sanitization — ComfyUICWE-79 | 8.2 | High | 2026-07-31 |
| CVE-2026-56671 | ComfyUI: Path traversal in /experiment/models/preview allows arbitrary image file read — ComfyUICWE-22 | 7.5 | High | 2026-07-31 |
| CVE-2026-56670 | ComfyUI: Stored XSS via SVG file upload on the /view endpoint — ComfyUICWE-79 | 8.2 | High | 2026-07-31 |
| CVE-2026-22777 | ComfyUI-Manager is Vulnerable to CRLF Injection in Configuration Handler — ComfyUI-ManagerCWE-93 | 7.5 | High | 2026-01-10 |
This page lists every published CVE security advisory associated with Comfy-Org. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.