What is CVE-2026-56671?
In ComfyUI versions prior to 0.28.0, the `get_model_preview` function in `app/model_manager.py` joins an unrestricted filename from a route capture to the model directory without a containment check. This vulnerability allows an unauthenticated remote attacker to read arbitrary files from the filesystem. Affected ComfyUI users are advised to update to version 0.28.0 or later immediately.
Azərbaycanca: ComfyUI proqramının 0.28.0 versiyasından əvvəlki versiyalarında `app/model_manager.py` faylındakı `get_model_preview` funksiyası fayl adını təhlükəsizlik yoxlaması olmadan model qovluğuna birləşdirir. Bu boşluq autentifikasiya olunmamış uzaqdan hücumçuya fayl sistemindəki faylları oxumağa imkan verir. Təsirə məruz qalan ComfyUI istifadəçilərinin ən qısa zamanda 0.28.0 və ya daha yuxarı versiyaya yeniləməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
What functionality does the CVE-2026-56671 vulnerability affect in ComfyUI?
This vulnerability impacts the `get_model_preview` function in `app/model_manager.py`, as it joins a filename to the model directory without a containment check.
What action can an attacker take if CVE-2026-56671 is exploited?
An unauthenticated remote attacker can read arbitrary files from the filesystem.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.