PT-2026-66677 · Comfyui · Comfyui

CVE-2026-56670

·

Published

2026-07-31

·

Updated

2026-08-21

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions ComfyUI versions prior to 0.28.0
Description The /view endpoint serves uploaded SVG files inline due to the absence of image/svg+xml and related XML content types from the dangerous-content-type handling. This allows for stored cross-site scripting (XSS), a technique where malicious scripts are permanently stored on the target server and executed in the browser of a user visiting the affected page.
Recommendations Update to version 0.28.0.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56670
GHSA-RJ8C-C4P8-3C5H
OPENSUSE-SU-2026:11562-1

Affected Products

Comfyui