Products: 2
    Vulnerabilities: 15
    Known Exploited: 0
    1
    Critical Level Threats
    7
    High Level Threats
    5
    Medium Level Threats
    2
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-68771

    ComfyUI 0.23.0 Unauthenticated RCE via LoadTrainingDataset Pickle Deserialization

    Last Modified: Aug 14, 2026
    Published: Jul 31, 2026

    CVE-2026-56673

    ComfyUI: Path traversal in LoadImage via the /prompt API allows arbitrary file existence probing and image exfiltration

    Last Modified: Aug 02, 2026
    Published: Jul 31, 2026

    CVE-2026-56672

    ComfyUI: Stored XSS via /userdata/{file} due to Missing Content-Type Sanitization

    Last Modified: Aug 02, 2026
    Published: Jul 31, 2026

    CVE-2026-56671

    ComfyUI: Path traversal in /experiment/models/preview allows arbitrary image file read

    Last Modified: Aug 02, 2026
    Published: Jul 31, 2026

    CVE-2026-56670

    ComfyUI: Stored XSS via SVG file upload on the /view endpoint

    Last Modified: Aug 02, 2026
    Published: Jul 31, 2026
    Items Per Page
    Comfy Vulnerabilities & Security CVEs | CVE-DB