Vulnerabilities in Comfy-Org
6 resultsVexday analysis
A Comfy-Org apresenta apenas 1 vulnerabilidade registrada na base, relacionada a CWE-93, sem exposição a exploração ativa. O risco é mínimo considerando o volume muito baixo de ocorrências e a ausência de impacto crítico ou interesse ofensivo recente.
CVE-2026-56671HIGHComfyUI: Path traversal in /experiment/models/preview allows arbitrary image file readEPSS 0.7%CVE-2026-68771CRITICALComfyUI 0.23.0 Unauthenticated RCE via LoadTrainingDataset Pickle DeserializationEPSS 0.6%CVE-2026-56673HIGHComfyUI: Path traversal in LoadImage via the /prompt API allows arbitrary file existence probing and image exfiltrationEPSS 0.4%CVE-2026-22777HIGHComfyUI-Manager is Vulnerable to CRLF Injection in Configuration HandlerEPSS 0.3%CVE-2026-56672HIGHComfyUI: Stored XSS via /userdata/{file} due to Missing Content-Type SanitizationEPSS 0.2%CVE-2026-56670HIGHComfyUI: Stored XSS via SVG file upload on the /view endpointEPSS 0.2%