Unsafe Deserialization Vulnerability in ComfyUI by ComfyOrg

⚠️ CVE-Referenzen: CVE-2026-68771
Comfy-org - Comfyui - CRITICAL - CVE-2026-68771. ComfyUI v0.23.0 is prone to an unsafe deserialization vulnerability within the LoadTrainingDataset node. This flaw enables unauthenticated remote attackers to upload specially crafted pickle files, specifically through the POST /upload/image endpoint, leading to the execution of arbitrary Python code. By queuing a workflow graph via POST /prompt that references the malicious shard_*.pkl file, attackers can exploit the deserialization process, allowing the execution of unauthorized commands with the privileges of the ComfyUI process user.
Quelle: securityvulnerability.io