{ "document": { "category": "csaf_vex", "csaf_version": "2.0", "lang": "en-US", "publisher": { "category": "coordinator", "contact_details": "https://www.cisa.gov/report", "issuing_authority": "CISA", "name": "CISA", "namespace": "https://www.cisa.gov/" }, "title": "ComfyUI stored XSS and path traversal vulnerabilities", "tracking": { "current_release_date": "2026-08-26T15:21:45Z", "generator": { "engine": { "name": "VINCE-NT", "version": "1.15.0+build.101" } }, "id": "VA-26-238-01", "initial_release_date": "2026-08-26T15:21:45Z", "status": "final", "version": "1.0.0", "revision_history": [ { "number": "1.0.0", "summary": "Initial publication", "date": "2026-08-26T15:21:45Z" } ] }, "distribution": { "tlp": { "label": "WHITE" } }, "notes": [ { "text": "All information products included in [https://github.com/cisagov/CSAF/tree/develop/csaf_files/IT/white](https://github.com/cisagov/CSAF/tree/develop/csaf_files/IT/white) are provided \\\"as is\\\" for informational purposes only. The Department of Homeland Security (DHS) does not provide any warranties of any kind regarding any information contained within. DHS does not endorse any commercial product or service, referenced in this product or otherwise. Further dissemination of this product is governed by the Traffic Light Protocol (TLP) marking in the header. For more information about TLP, see [https://us-cert.cisa.gov/tlp/](https://us-cert.cisa.gov/tlp/).", "title": "Legal Notice", "category": "legal_disclaimer" }, { "text": "Worldwide", "title": "Countries and Areas Deployed", "category": "other" }, { "text": "Information Technology", "title": "Critical Infrastructure Sectors", "category": "other" }, { "text": "ComfyUI contains multiple vulnerabilities, with the most severe impact being that a remote, unauthenticated attacker could read image-decodable files and probe arbitrary host paths.", "title": "Risk Evaluation", "category": "summary" }, { "text": "Fixed in 0.28.0.", "title": "Recommended Practices", "category": "general" }, { "text": "United States", "title": "Company Headquarters Location", "category": "other" } ], "references": [ { "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-238-01.json", "summary": "Vulnerability Advisory VA-26-238-01 CSAF", "category": "self" } ] }, "product_tree": { "branches": [ { "category": "vendor", "name": "Comfy-Org", "branches": [ { "category": "product_name", "name": "ComfyUI", "branches": [ { "category": "product_version_range", "name": "<0.28.0", "product": { "name": "Comfy-Org ComfyUI <0.28.0", "product_id": "CSAFPID-0001" } }, { "category": "product_version", "name": "0.28.0", "product": { "name": "Comfy-Org ComfyUI 0.28.0", "product_id": "CSAFPID-0002" } } ] }, { "category": "product_name", "name": "ComfyUI", "branches": [ { "category": "product_version_range", "name": "<0.28.0", "product": { "name": "Comfy-Org ComfyUI <0.28.0", "product_id": "CSAFPID-0003" } }, { "category": "product_version", "name": "0.28.0", "product": { "name": "Comfy-Org ComfyUI 0.28.0", "product_id": "CSAFPID-0004" } } ] }, { "category": "product_name", "name": "ComfyUI", "branches": [ { "category": "product_version_range", "name": "<0.28.0", "product": { "name": "Comfy-Org ComfyUI <0.28.0", "product_id": "CSAFPID-0005" } }, { "category": "product_version", "name": "0.28.0", "product": { "name": "Comfy-Org ComfyUI 0.28.0", "product_id": "CSAFPID-0006" } } ] }, { "category": "product_name", "name": "ComfyUI", "branches": [ { "category": "product_version_range", "name": "<0.28.0", "product": { "name": "Comfy-Org ComfyUI <0.28.0", "product_id": "CSAFPID-0007" } }, { "category": "product_version", "name": "0.28.0", "product": { "name": "Comfy-Org ComfyUI 0.28.0", "product_id": "CSAFPID-0008" } } ] } ] } ] }, "vulnerabilities": [ { "cve": "CVE-2026-56670", "cwe": { "id": "CWE-79", "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" }, "notes": [ { "category": "summary", "text": "ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpoint served uploaded SVG files inline because image/svg+xml and related XML content types were absent from the dangerous-content-type handling, allowing stored cross-site scripting in the ComfyUI origin. This issue is fixed in version 0.28.0.", "title": "Description" }, { "category": "details", "title": "SSVC", "text": "SSVCv2/E:N/A:N/T:P/2026-08-26T14:20:29Z/" } ], "title": "ComfyUI: Stored XSS via SVG file upload on the /view endpoint", "product_status": { "known_affected": [ "CSAFPID-0001" ], "fixed": [ "CSAFPID-0002" ] }, "references": [ { "category": "external", "summary": "github.com", "url": "https://github.com/Comfy-Org/ComfyUI/security/advisories/GHSA-rj8c-c4p8-3c5h" }, { "category": "external", "summary": "github.com", "url": "https://github.com/Comfy-Org/ComfyUI/commit/96e0e3585b41e1417442eaa14ec57f7b4ffcb5e0" }, { "category": "external", "summary": "github.com", "url": "https://github.com/Comfy-Org/ComfyUI/releases/tag/v0.28.0" }, { "category": "external", "summary": "VA-26-238-01 CSAF", "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-238-01.json" }, { "category": "external", "summary": "CVE-2026-56670", "url": "https://www.cve.org/CVERecord?id=CVE-2026-56670" } ], "scores": [ { "cvss_v3": { "baseScore": 8.2, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N", "version": "3.1" }, "products": [ "CSAFPID-0001" ] } ], "remediations": [ { "category": "vendor_fix", "details": "Fixed in 0.28.0.", "url": "https://github.com/Comfy-Org/ComfyUI/releases/tag/v0.28.0", "product_ids": [ "CSAFPID-0001" ], "date": "2026-07-15T00:00:00Z" }, { "category": "vendor_fix", "details": "Fixed in 0.28.0.", "url": "https://github.com/Comfy-Org/ComfyUI/releases/tag/v0.28.0", "product_ids": [ "CSAFPID-0002" ], "date": "2026-07-15T00:00:00Z" } ], "release_date": "2026-07-31T00:00:00Z" }, { "cve": "CVE-2026-56671", "cwe": { "id": "CWE-22", "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')" }, "notes": [ { "category": "summary", "text": "ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, get_model_preview in app/model_manager.py joins an unrestricted filename route capture to a selected model directory without a containment check, allowing an unauthenticated remote attacker to use traversal, encoded traversal, absolute paths, or an unbounded path_index to read image-decodable files and enumerate host paths. get_model_preview (app/model_manager.py) built the path with os.path.join(folder, filename) where filename is an unrestricted {filename:.*} route capture. Literal ../, percent-encoded %2e%2e%2f, and absolute paths all escaped the model directory; path_index was also unbounded. The target file is piped through Pillow and re-encoded as WEBP, so disclosure is limited to image-decodable files plus a file-existence/enumeration oracle (and internal-path leakage via path_index errors). This issue is fixed in version 0.28.0.", "title": "Description" }, { "category": "details", "title": "SSVC", "text": "SSVCv2/E:N/A:Y/T:P/2026-08-26T14:20:46Z/" } ], "title": "ComfyUI: Path traversal in /experiment/models/preview allows arbitrary image file read", "product_status": { "known_affected": [ "CSAFPID-0001" ], "fixed": [ "CSAFPID-0002" ] }, "references": [ { "category": "external", "summary": "github.com", "url": "https://github.com/Comfy-Org/ComfyUI/security/advisories/GHSA-pj59-g5vv-74q4" }, { "category": "external", "summary": "github.com", "url": "https://github.com/Comfy-Org/ComfyUI/pull/14734" }, { "category": "external", "summary": "github.com", "url": "https://github.com/Comfy-Org/ComfyUI/releases/tag/v0.28.0" }, { "category": "external", "summary": "VA-26-238-01 CSAF", "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-238-01.json" }, { "category": "external", "summary": "CVE-2026-56671", "url": "https://www.cve.org/CVERecord?id=CVE-2026-56671" } ], "scores": [ { "cvss_v3": { "baseScore": 7.5, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "version": "3.1" }, "products": [ "CSAFPID-0001" ] } ], "remediations": [ { "category": "vendor_fix", "details": "Fixed in 0.28.0.", "url": "https://github.com/Comfy-Org/ComfyUI/releases/tag/v0.28.0", "product_ids": [ "CSAFPID-0001" ], "date": "2026-07-15T00:00:00Z" }, { "category": "vendor_fix", "details": "Fixed in 0.28.0.", "url": "https://github.com/Comfy-Org/ComfyUI/releases/tag/v0.28.0", "product_ids": [ "CSAFPID-0002" ], "date": "2026-07-15T00:00:00Z" } ], "release_date": "2026-07-31T00:00:00Z" }, { "cve": "CVE-2026-56672", "cwe": { "id": "CWE-79", "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" }, "notes": [ { "category": "summary", "text": "ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-controlled HTML and SVG files with extension-derived content types, allowing stored cross-site scripting in the ComfyUI origin and access to browser-stored API tokens, settings, workflows, and authenticated-equivalent API calls. The handler used web.FileResponse(path), so an uploaded .html/.svg was served as text/html/image/svg+xml. POST /userdata stores arbitrary request bodies (confined to the user's userdata directory). When a victim navigated to the file URL, the embedded script executed same-origin. The /view endpoint already forced dangerous MIME types to download; that protection had never been applied to /userdata. This issue is fixed in version 0.28.0.", "title": "Description" }, { "category": "details", "title": "SSVC", "text": "SSVCv2/E:N/A:N/T:P/2026-08-26T14:20:54Z/" } ], "title": "ComfyUI: Stored XSS via /userdata/{file} due to Missing Content-Type Sanitization", "product_status": { "known_affected": [ "CSAFPID-0001" ], "fixed": [ "CSAFPID-0002" ] }, "references": [ { "category": "external", "summary": "github.com", "url": "https://github.com/Comfy-Org/ComfyUI/security/advisories/GHSA-53g8-45wq-pcv8" }, { "category": "external", "summary": "github.com", "url": "https://github.com/Comfy-Org/ComfyUI/commit/96e0e3585b41e1417442eaa14ec57f7b4ffcb5e0" }, { "category": "external", "summary": "github.com", "url": "https://github.com/Comfy-Org/ComfyUI/releases/tag/v0.28.0" }, { "category": "external", "summary": "VA-26-238-01 CSAF", "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-238-01.json" }, { "category": "external", "summary": "CVE-2026-56672", "url": "https://www.cve.org/CVERecord?id=CVE-2026-56672" } ], "scores": [ { "cvss_v3": { "baseScore": 8.2, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N", "version": "3.1" }, "products": [ "CSAFPID-0001" ] } ], "remediations": [ { "category": "vendor_fix", "details": "Fixed in 0.28.0.", "url": "https://github.com/Comfy-Org/ComfyUI/releases/tag/v0.28.0", "product_ids": [ "CSAFPID-0001" ], "date": "2026-07-15T00:00:00Z" }, { "category": "vendor_fix", "details": "Fixed in 0.28.0.", "url": "https://github.com/Comfy-Org/ComfyUI/releases/tag/v0.28.0", "product_ids": [ "CSAFPID-0002" ], "date": "2026-07-15T00:00:00Z" } ], "release_date": "2026-07-31T00:00:00Z" }, { "cve": "CVE-2026-56673", "cwe": { "id": "CWE-22", "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')" }, "notes": [ { "category": "summary", "text": "ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_paths.get_annotated_filepath and exists_annotated_filepath join workflow-controlled annotated filenames to a base directory without a containment check, allowing an unauthenticated crafted POST /prompt workflow using LoadImage or sibling nodes to probe arbitrary host paths and exfiltrate image-format files through /view. LoadImage defines a VALIDATE_INPUTS method, which causes the execution engine to skip COMBO (input-directory) validation. Affected nodes include LoadImage, LoadImageMask, LoadImageOutput, LoadAudio, LoadLatent, LoadVideo, and Load3D. This issue is fixed in version 0.28.0.", "title": "Description" }, { "category": "details", "title": "SSVC", "text": "SSVCv2/E:N/A:Y/T:P/2026-08-26T14:21:03Z/" } ], "title": "ComfyUI: Path traversal in LoadImage via the /prompt API allows arbitrary file existence probing and image exfiltration", "product_status": { "known_affected": [ "CSAFPID-0001" ], "fixed": [ "CSAFPID-0002" ] }, "references": [ { "category": "external", "summary": "github.com", "url": "https://github.com/Comfy-Org/ComfyUI/security/advisories/GHSA-rvxv-29p8-pxgq" }, { "category": "external", "summary": "github.com", "url": "https://github.com/Comfy-Org/ComfyUI/pull/14734" }, { "category": "external", "summary": "github.com", "url": "https://github.com/Comfy-Org/ComfyUI/releases/tag/v0.28.0" }, { "category": "external", "summary": "VA-26-238-01 CSAF", "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-238-01.json" }, { "category": "external", "summary": "CVE-2026-56673", "url": "https://www.cve.org/CVERecord?id=CVE-2026-56673" } ], "scores": [ { "cvss_v3": { "baseScore": 7.5, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "version": "3.1" }, "products": [ "CSAFPID-0001" ] } ], "remediations": [ { "category": "vendor_fix", "details": "Fixed in 0.28.0.", "url": "https://github.com/Comfy-Org/ComfyUI/releases/tag/v0.28.0", "product_ids": [ "CSAFPID-0001" ], "date": "2026-07-15T00:00:00Z" }, { "category": "vendor_fix", "details": "Fixed in 0.28.0.", "url": "https://github.com/Comfy-Org/ComfyUI/releases/tag/v0.28.0", "product_ids": [ "CSAFPID-0002" ], "date": "2026-07-15T00:00:00Z" } ], "release_date": "2026-07-31T00:00:00Z" } ] }