PT-2026-33687 · Comfyui · Comfyui

·

CVE-2026-6593

·

Published

2026-04-20

·

Updated

2026-04-21

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions ComfyUI versions prior to 0.13.0
Description A flaw in the View Endpoint component within the server.py file allows for remote cross site scripting. Cross site scripting is a type of security gap where malicious scripts are injected into otherwise trusted websites.
Recommendations Update to a version later than 0.13.0. As a temporary workaround, restrict access to the View Endpoint component to minimize the risk of exploitation.

Exploit

Fix

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6593

Affected Products

Comfyui