Unsafe Deserialization Vulnerability in ComfyUI by ComfyOrg
CVE-2026-68771

9.3CRITICAL

Key Information:

Vendor

Comfy-org

Status
Vendor
CVE Published:
31 July 2026

What is CVE-2026-68771?

ComfyUI v0.23.0 is prone to an unsafe deserialization vulnerability within the LoadTrainingDataset node. This flaw enables unauthenticated remote attackers to upload specially crafted pickle files, specifically through the POST /upload/image endpoint, leading to the execution of arbitrary Python code. By queuing a workflow graph via POST /prompt that references the malicious shard_*.pkl file, attackers can exploit the deserialization process, allowing the execution of unauthorized commands with the privileges of the ComfyUI process user.

Affected Version(s)

ComfyUI 0 <= 0.23.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bofei Chen
.