top of page
perceptive_background_267k.jpg

ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpoint served uploaded SVG files inline bec…

Published:

31 juli 2026 om 00:00:00

Alert date:

31 juli 2026 om 09:02:41

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Emerging Technologies

ComfyUI, a modular diffusion model GUI and backend, contained a stored cross-site scripting (XSS) vulnerability prior to version 0.28.0. The /view endpoint served uploaded SVG files inline without properly handling image/svg+xml and related XML content types as dangerous. This omission allowed attackers to upload malicious SVG files that would execute scripts in the ComfyUI origin context. The vulnerability is classified as stored XSS, meaning the malicious payload persists on the server and affects any user who views the content. The issue was addressed in version 0.28.0 by adding SVG and XML content types to the dangerous-content-type handling logic. A security advisory was published on GitHub along with the fix commit. Users are strongly advised to upgrade to version 0.28.0 or later to mitigate this risk.

Technical details

Mitigation steps:

Affected products:

ComfyUI

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page