What is CVE-2026-56670?
A stored cross-site scripting (XSS) vulnerability exists in ComfyUI due to the absence of dangerous-content-type handling for SVG and XML content types at the /view endpoint. This affects versions prior to 0.28.0. Users should immediately upgrade to version 0.28.0 or later.
Azərbaycanca: ComfyUI interfeysində yüklənmiş SVG faylları üçün /view endpoint-də təhlükəli məzmun tiplərinin düzgün işlənməməsi səbəbindən stored cross-site scripting (XSS) zəifliyi mövcuddur. Bu zəiflik 0.28.0 versiyasından əvvəlki versiyalara təsir edir. İstifadəçilərə dərhal ComfyUI-ni 0.28.0 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of ComfyUI are affected by CVE-2026-56670?
This stored XSS vulnerability affects all versions of ComfyUI prior to 0.28.0.
How can I protect against CVE-2026-56670?
It is recommended to immediately upgrade ComfyUI to version 0.28.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.