Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2540▼ 352 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.20% | — | ComfyuiAI | 16/9/2026 | 22/9/2026 | ComfyUI before 0.30.0 fails to sanitize folder_name input in dataset save nodes, allowing attackers to write files to arbitrary paths outside the output directory. Attackers can load a crafted workflow that writes attacker-controlled content to arbitrary locations, enabling code execution through modified startup… | |
| Aplazada | Baja (1.9) | 0.17% | — | Nikolaibibo Claude-comfyui-mcpAI | 9/8/2026 | 13/8/2026 | A vulnerability was identified in Nikolaibibo claude-comfyui-mcp 1.0.0. Affected is the function copyFileSync of the file src/tools/utils.ts of the component comfy_upload_image. Such manipulation of the argument image_path leads to path traversal. An attack has to be approached locally. The project was informed of the… | |
| Aplazada | Crítica (9.3) | 1.1% | — | ComfyuiAI | 31/7/2026 | 9/9/2026 | ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserialization. Attackers can upload a malicious shard_*.pkl file via the unauthenticated… | |
| Pendiente de análisis | Alta (7.5) | 0.63% | — | ComfyuiAI | 31/7/2026 | 8/9/2026 | ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_paths.get_annotated_filepath and exists_annotated_filepath join workflow-controlled annotated filenames to a base directory without a containment check, allowing an unauthenticated crafted POST /prompt… | |
| Pendiente de análisis | Alta (8.2) | 0.40% | — | ComfyuiAI | 31/7/2026 | 8/9/2026 | ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-controlled HTML and SVG files with extension-derived content types, allowing stored cross-site scripting in the ComfyUI origin and access to browser-stored API tokens, settings, workflows, and… | |
| Pendiente de análisis | Alta (7.5) | 0.97% | — | ComfyuiAI | 31/7/2026 | 8/9/2026 | ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, get_model_preview in app/model_manager.py joins an unrestricted filename route capture to a selected model directory without a containment check, allowing an unauthenticated remote attacker to use traversal,… | |
| Pendiente de análisis | Alta (8.2) | 0.40% | — | ComfyuiAI | 31/7/2026 | 8/9/2026 | ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpoint served uploaded SVG files inline because image/svg+xml and related XML content types were absent from the dangerous-content-type handling, allowing stored cross-site scripting in the ComfyUI… | |
| Aplazada | Baja (1.3) | 0.36% | — | Aidc-ai Comfyui-copilotAI | 28/6/2026 | 29/6/2026 | A flaw has been found in AIDC-AI ComfyUI-Copilot up to 2.0.28. This issue affects some unknown processing of the file backend/controller/conversation_api.py of the component Workflow Checkpoint Restore Handler. Executing a manipulation can lead to improper control of resource identifiers. The attack may be performed… | |
| Aplazada | Baja (2) | 0.33% | — | ComfyuiAI | 20/4/2026 | 17/6/2026 | A vulnerability was found in ComfyUI up to 0.13.0. Affected by this issue is some unknown functionality of the file server.py of the component View Endpoint. Performing a manipulation results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been made public and could be used.… | |
| Aplazada | Baja (2) | 0.40% | — | ComfyuiAI | 20/4/2026 | 17/6/2026 | A vulnerability has been found in ComfyUI up to 0.13.0. Affected by this vulnerability is the function getuserdata of the file app/user_manager.py of the component userdata Endpoint. Such manipulation leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed to the public and… | |
| Aplazada | Baja (2.1) | 0.52% | — | ComfyuiAI | 20/4/2026 | 17/6/2026 | A flaw has been found in ComfyUI up to 0.13.0. Affected is the function folder_paths.get_annotated_filepath of the file folder_paths.py of the component LoadImage Node. This manipulation of the argument Name causes path traversal. Remote exploitation of the attack is possible. The exploit has been published and may be… | |
| Aplazada | Baja (2.1) | 0.52% | — | ComfyuiAI | 20/4/2026 | 17/6/2026 | A vulnerability was detected in ComfyUI up to 0.13.0. This impacts the function get_model_preview of the file app/model_manager.py of the component Model Preview Endpoint. The manipulation results in path traversal. The attack may be launched remotely. The exploit is now public and may be used. The vendor was… | |
| Aplazada | Baja (2.1) | 0.22% | — | ComfyuiAI | 20/4/2026 | 17/6/2026 | A security vulnerability has been detected in ComfyUI up to 0.13.0. This affects the function create_origin_only_middleware of the file server.py. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was… | |
| Analizada | Alta (7.5) | 0.35% | — | Comfyui-manager | 10/1/2026 | 17/6/2026 | ComfyUI-Manager is an extension designed to enhance the usability of ComfyUI. Prior to versions 3.39.2 and 4.0.5, an attacker can inject special characters into HTTP query parameters to add arbitrary configuration values to the config.ini file. This can lead to security setting tampering or modification of application… | |
| Analizada | Alta (7.5) | 1.4% | — | Comfyui-manager | 5/1/2026 | 17/6/2026 | An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration and critical data. This was due to the application storing its files in an insufficiently protected location that was accessible via the web interface | |
| Aplazada | Alta (8.8) | 0.28% | — | VisionatrixAIComfyuiAITiangolo FastapiAI | 23/6/2025 | 17/6/2026 | Visionatrix is an AI Media processing tool using ComfyUI. In versions 1.5.0 to before 2.5.1, the /docs/flows endpoint is vulnerable to a Reflected XSS (Cross-Site Scripting) attack allowing full takeover of the application and exfiltration of secrets stored in the application. The implementation uses the… | |
| Aplazada | Baja (1.3) | 0.43% | — | ComfyuiAI | 16/6/2025 | 17/6/2026 | A vulnerability was found in comfyanonymous comfyui 0.3.40. It has been classified as problematic. Affected is the function set_attr of the file /comfy/utils.py. The manipulation leads to dynamically-determined object attributes. It is possible to launch the attack remotely. The complexity of an attack is rather high.… | |
| Aplazada | Baja (2.1) | 0.38% | — | ComfyuiAI | 15/6/2025 | 17/6/2026 | A vulnerability was found in comfyanonymous comfyui up to 0.3.39. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /upload/image of the component Incomplete Fix CVE-2024-10099. The manipulation of the argument image leads to cross site scripting. The attack… | |
| Analizada | Alta (7.5) | 0.75% | — | Comfyui | 20/3/2025 | 17/6/2026 | comfyanonymous/comfyui version v0.2.4 suffers from a non-blind Server-Side Request Forgery (SSRF) vulnerability. This vulnerability can be exploited by combining the REST APIs `POST /internal/models/download` and `GET /view`, allowing attackers to abuse the victim server's credentials to access unauthorized web… | |
| Analizada | Media (6.5) | 0.22% | — | Comfyui | 20/3/2025 | 17/6/2026 | A CSRF vulnerability exists in comfyanonymous/comfyui versions up to v0.2.2. This vulnerability allows attackers to host malicious websites that, when visited by authenticated ComfyUI users, can perform arbitrary API requests on behalf of the user. This can be exploited to perform actions such as uploading arbitrary… | |
| Aplazada | Crítica (10) | 0.59% | — | Comfyui ACE NodesAI | 13/12/2024 | 17/6/2026 | ComfyUI-Ace-Nodes is vulnerable to Code Injection. The ACE_ExpressionEval node contains an eval() in its entrypoint function that accepts arbitrary user-controlled data. A user can create a workflow that results in executing arbitrary code on the server. | |
| Aplazada | Crítica (10) | 0.57% | — | Comfyui Bmad NodesAI | 13/12/2024 | 17/6/2026 | ComfyUI-Bmad-Nodes is vulnerable to Code Injection. The issue stems from a validation bypass in the BuildColorRangeHSVAdvanced, FilterContour and FindContour custom nodes. In the entrypoint function to each node, there’s a call to eval which can be triggered by generating a workflow that injects a crafted string into… | |
| Aplazada | Crítica (9.2) | 1.0% | — | Comfyui Impact PackAI | 12/12/2024 | 17/6/2026 | ComfyUI-Impact-Pack is vulnerable to Path Traversal. The issue stems from missing validation of the `image.filename` field in a POST request sent to the `/upload/temp` endpoint added by the extension to the server. This results in writing arbitrary files to the file system which may, under some conditions, result in… | |
| Analizada | Media (6.1) | 0.37% | — | Comfyui | 17/10/2024 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in comfyanonymous/comfyui version 0.2.2 and possibly earlier. The vulnerability occurs when an attacker uploads an HTML file containing a malicious XSS payload via the `/api/upload/image` endpoint. The payload is executed when the file is viewed through the… |