Security: Comfy-Org/ComfyUI
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Stored XSS via SVG file upload on the /view endpointGHSA-rj8c-c4p8-3c5h published
Jul 15, 2026 by mattmilleraiHigh -
Stored XSS via /userdata/{file} due to missing Content-Type sanitizationGHSA-53g8-45wq-pcv8 published
Jul 15, 2026 by mattmilleraiHigh -
Path traversal in LoadImage via the /prompt API allows arbitrary file existence probing and image exfiltrationGHSA-rvxv-29p8-pxgq published
Jul 15, 2026 by mattmilleraiHigh -
Path traversal in /experiment/models/preview allows arbitrary image file readGHSA-pj59-g5vv-74q4 published
Jul 15, 2026 by mattmilleraiHigh