PT-2026-66680 · Comfyui · Comfyui

CVE-2026-56673

·

Published

2026-07-31

·

Updated

2026-07-31

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ComfyUI versions prior to 0.28.0
Description An issue exists where the functions get annotated filepath() and exists annotated filepath() in the folder paths module join workflow-controlled filenames to a base directory without performing a containment check. This allows an unauthenticated user to send a crafted POST '/prompt' workflow using the LoadImage node or similar nodes to probe arbitrary paths on the host system and exfiltrate image-format files via the '/view' endpoint. The LoadImage node implements a VALIDATE INPUTS method, which leads the execution engine to bypass validation for the COMBO input directory. Affected nodes include LoadImage, LoadImageMask, LoadImageOutput, LoadAudio, LoadLatent, LoadVideo, and Load3D.
Recommendations Update ComfyUI to version 0.28.0. Restrict the use of the LoadImage, LoadImageMask, LoadImageOutput, LoadAudio, LoadLatent, LoadVideo, and Load3D nodes as a temporary mitigation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56673
GHSA-RVXV-29P8-PXGQ

Affected Products

Comfyui