Path Traversal Vulnerability in ComfyUI by ComfyOrg
CVE-2026-56673

7.5HIGH

Key Information:

Vendor

Comfy-org

Status
Vendor
CVE Published:
31 July 2026

What is CVE-2026-56673?

A significant path traversal vulnerability exists in ComfyUI, a modular GUI and API platform, allowing unauthenticated users to exploit specific nodes. Before version 0.28.0, certain workflow-controlled annotated filenames could be combined with a base directory without proper containment checks. This flaw enables attackers to use crafted POST requests via nodes like LoadImage, LoadAudio, and LoadVideo to access arbitrary host paths and exfiltrate files in image formats. The vulnerability has been addressed in version 0.28.0, where enhanced input validation measures prevent unauthorized access.

Affected Version(s)

ComfyUI < 0.28.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.