ComfyUI disclosed and patched CVE-2026-56672, a high-severity stored cross-site scripting flaw affecting versions prior to 0.28.0. The bug allowed attacker-controlled HTML or SVG files uploaded through /userdata/{file} to be served back with extension-derived MIME types, causing script execution in the ComfyUI origin when a victim opened the file URL. A successful attack could expose browser-stored API tokens, settings, and workflows, and let an attacker perform authenticated-equivalent API actions. The issue was rated CVSS 8.2 and required user interaction for exploitation.
The fix shipped in ComfyUI 0.28.0 as part of security advisory GHSA-779p-m5rp-r4h4, which also addressed additional file-handling weaknesses. The patch centralized dangerous MIME-type detection and forced risky content on /userdata/{file}, /view, and /api/assets/{id}/content to download as application/octet-stream, while adding Content-Disposition: attachment and X-Content-Type-Options: nosniff headers. Developers also hardened /experiment/models/preview and related path-resolution logic against path traversal, symlink escape, invalid path indexes, empty filenames, and null-byte edge cases, with regression tests added for SVG, XML, HTML, JavaScript, and preview-file abuse scenarios.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A ComfyUI commit for security advisory GHSA-779p-m5rp-r4h4 added protections for dangerous MIME types on /userdata/{file} and other routes, forcing risky content to download and adding nosniff and attachment headers. The patch also addressed multiple path traversal and file-handling issues and included regression tests.
CVE-2026-56672 was disclosed as a high-severity stored XSS vulnerability in ComfyUI versions prior to 0.28.0. The flaw allowed attacker-controlled HTML or SVG served by /userdata/{file} to execute in the ComfyUI origin when a victim visited the file URL, and the issue was noted as fixed in version 0.28.0.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.