


Perceptive Security
SOC/SIEM Consultancy

ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpoint served uploaded SVG files inline bec…
Published:
31 juli 2026 om 00:00:00
Alert date:
31 juli 2026 om 09:02:41
Source:
nvd.nist.gov
Web Technologies, Emerging Technologies
ComfyUI, a modular diffusion model GUI and backend, contained a stored cross-site scripting (XSS) vulnerability prior to version 0.28.0. The /view endpoint served uploaded SVG files inline without properly handling image/svg+xml and related XML content types as dangerous. This omission allowed attackers to upload malicious SVG files that would execute scripts in the ComfyUI origin context. The vulnerability is classified as stored XSS, meaning the malicious payload persists on the server and affects any user who views the content. The issue was addressed in version 0.28.0 by adding SVG and XML content types to the dangerous-content-type handling logic. A security advisory was published on GitHub along with the fix commit. Users are strongly advised to upgrade to version 0.28.0 or later to mitigate this risk.
Technical details
Mitigation steps:
Affected products:
ComfyUI
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-56670
https://github.com/Comfy-Org/ComfyUI/commit/96e0e3585b41e1417442eaa14ec57f7b4ffcb5e0
https://github.com/Comfy-Org/ComfyUI/releases/tag/v0.28.0
https://github.com/Comfy-Org/ComfyUI/security/advisories/GHSA-rj8c-c4p8-3c5h
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
