A critical remote code execution flaw tracked as CVE-2026-68771 affects ComfyUI v0.23.0 through unsafe deserialization in the LoadTrainingDataset node. An attacker can reportedly upload a crafted pickle file to the unauthenticated POST /upload/image endpoint and then trigger deserialization through POST /prompt, causing torch.load to process an attacker-controlled shard_*.pkl file. Because Python pickle deserialization can invoke arbitrary code via mechanisms such as __reduce__, successful exploitation can lead to command execution with the privileges of the ComfyUI process.
A related ComfyUI code change shows the project hardened dataset shard loading by replacing torch.load(f) with torch.load(f, weights_only=True) in comfy_extras/nodes_dataset.py, limiting deserialization to weights-only data and reducing exposure to malicious serialized objects. Reported mitigations include upgrading to a version that incorporates the safer loading behavior, avoiding untrusted pickle files, and reviewing node security settings on exposed deployments.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A CVE entry disclosed CVE-2026-68771, a critical unauthenticated remote code execution flaw in ComfyUI v0.23.0 caused by unsafe deserialization in the LoadTrainingDataset node. The disclosure states attackers can upload a crafted pickle file via `POST /upload/image` and trigger code execution through `POST /prompt`.
A ComfyUI code commit changed `torch.load(f)` to `torch.load(f, weights_only=True)` in `comfy_extras/nodes_dataset.py`, reducing unsafe deserialization risk when loading training-dataset shard files.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.