โ† All reports

ComfyUI up to version 0.13.0 contains vulnerabilities that allow for cross-site scripting and path traversal attacks.

CybersecurityTechnologyConflictApr 20, 2026score 0.173 posts ยท 0 replies across 1 instances
The thread discusses multiple vulnerabilities found in ComfyUI up to version 0.13.0, including cross-site scripting and path traversal issues, which pose security risks. These vulnerabilities highlight potential weaknesses in the software's functionality that could be exploited.

Claims

ComfyUI up to version 0.13.0 contains vulnerabilities that allow for cross-site scripting and path traversal attacks.
Parent: CybersecurityEntity: ComfyUIImpact: negativeDate: Apr 20, 2026Target: ComfyUI's security posture

Source posts

@[email protected]
๐Ÿšจ EUVD-2026-23739 ๐Ÿ“Š Score: 5.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: comfyui, comfyui, comfyui (+10 more) ๐Ÿ“… Updated: 2026-04-20 ๐Ÿ“ A vulnerability was found in ComfyUI up to 0.13.0. Affected by this issue is some unknown functionality of the file server.py of the component View Endpoint. Performing a manipulation results in cross site scripting. The attack is possible to be c... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23739 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 20, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-23733 ๐Ÿ“Š Score: 5.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: comfyui, comfyui, comfyui (+10 more) ๐Ÿ“… Updated: 2026-04-20 ๐Ÿ“ A vulnerability was detected in ComfyUI up to 0.13.0. This impacts the function get_model_preview of the file app/model_manager.py of the component Model Preview Endpoint. The manipulation results in path traversal. The attack may be launched remo... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23733 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 20, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-23737 ๐Ÿ“Š Score: 5.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: comfyui, comfyui, comfyui (+10 more) ๐Ÿ“… Updated: 2026-04-20 ๐Ÿ“ A vulnerability has been found in ComfyUI up to 0.13.0. Affected by this vulnerability is the function getuserdata of the file app/user_manager.py of the component userdata Endpoint. Such manipulation leads to cross site scripting. The attack can ... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23737 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 20, 2026
#cybersecurity#infosec#euvd#cve#vulnerability