PT-2026-94088 · Comfy Org+1 · Comfyui
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ComfyUI versions prior to 0.30.0
Description
Insufficient sanitization of the
folder name input in dataset save nodes allows attackers to write files to arbitrary paths outside the designated output directory. By loading a crafted workflow, an attacker can write controlled content to arbitrary locations, which may lead to code execution by modifying startup files or package initializers.Recommendations
Update ComfyUI to version 0.30.0 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Comfyui