


Perceptive Security
SOC/SIEM Consultancy

ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitra…
Published:
31 July 2026 at 00:00:00
Alert date:
1 August 2026 at 01:01:11
Source:
nvd.nist.gov
Web Technologies, Emerging Technologies, Zero-Day Vulnerabilities
ComfyUI v0.23.0 contains a critical unsafe deserialization vulnerability in the LoadTrainingDataset node. Unauthenticated remote attackers can exploit this by uploading a crafted pickle file via the unauthenticated POST /upload/image endpoint. The attacker then queues a workflow graph via POST /prompt referencing the uploaded malicious file. This triggers torch.load to deserialize the attacker-controlled pickle payload using Python's __reduce__ mechanism. The result is arbitrary Python code execution running as the ComfyUI process user. No authentication is required at any stage of the attack chain, making this highly exploitable. A fix has been committed to the ComfyUI GitHub repository.
Technical details
Mitigation steps:
Affected products:
ComfyUI v0.23.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-68771
https://github.com/Comfy-Org/ComfyUI
https://github.com/Comfy-Org/ComfyUI/commit/94ee49b1612824366a8631ea069b2a1fa5c73720
https://github.com/Comfy-Org/ComfyUI/pull/14543
https://www.vulncheck.com/advisories/comfyui-unauthenticated-rce-via-loadtrainingdataset-pickle-deserialization
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
