Path Traversal Vulnerability in ComfyUI by ComfyOrg
CVE-2026-56673
7.5HIGH
What is CVE-2026-56673?
A significant path traversal vulnerability exists in ComfyUI, a modular GUI and API platform, allowing unauthenticated users to exploit specific nodes. Before version 0.28.0, certain workflow-controlled annotated filenames could be combined with a base directory without proper containment checks. This flaw enables attackers to use crafted POST requests via nodes like LoadImage, LoadAudio, and LoadVideo to access arbitrary host paths and exfiltrate files in image formats. The vulnerability has been addressed in version 0.28.0, where enhanced input validation measures prevent unauthorized access.
Affected Version(s)
ComfyUI < 0.28.0
