ComfyUI patched a stored cross-site scripting vulnerability tracked as CVE-2026-56670 that allowed malicious SVG files uploaded to the platform to execute script in the application's origin when later rendered through the /view endpoint. The flaw affected versions prior to 0.28.0 because uploaded SVG content was served inline and image/svg+xml and related XML content types were not included in dangerous content-type handling, creating a path for attacker-controlled content to run in a victim's browser.
The issue is classified as CWE-79 and carries a CVSS v3.1 vector of AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N, indicating high confidentiality impact with user interaction required. ComfyUI addressed the bug in version 0.28.0, whose release notes also state that the update includes fixes for four vulnerabilities under GHSA-779p-m5rp-r4h4, alongside other security and stability improvements such as masking authorization headers in logs for Partner Nodes.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
ComfyUI released version 0.28.0, which included a security fix bundle referenced by advisory GHSA-779p-m5rp-r4h4. This release fixed CVE-2026-56670, a stored XSS issue affecting versions prior to 0.28.0.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.