PT-2026-66680 · Comfyui · Comfyui
CVE-2026-56673
·
Published
2026-07-31
·
Updated
2026-07-31
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ComfyUI versions prior to 0.28.0
Description
An issue exists where the functions
get annotated filepath() and exists annotated filepath() in the folder paths module join workflow-controlled filenames to a base directory without performing a containment check. This allows an unauthenticated user to send a crafted POST '/prompt' workflow using the LoadImage node or similar nodes to probe arbitrary paths on the host system and exfiltrate image-format files via the '/view' endpoint. The LoadImage node implements a VALIDATE INPUTS method, which leads the execution engine to bypass validation for the COMBO input directory. Affected nodes include LoadImage, LoadImageMask, LoadImageOutput, LoadAudio, LoadLatent, LoadVideo, and Load3D.Recommendations
Update ComfyUI to version 0.28.0.
Restrict the use of the
LoadImage, LoadImageMask, LoadImageOutput, LoadAudio, LoadLatent, LoadVideo, and Load3D nodes as a temporary mitigation.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Comfyui