What is CVE-2026-56672?
CVE-2026-56672: In ComfyUI versions prior to 0.28.0, the GET /userdata/{file} endpoint serves user-uploaded HTML/SVG files with extension-derived content types, enabling stored cross-site scripting (XSS) attacks. This can lead to theft of browser-stored API tokens, settings, and workflows. Affected instances should be upgraded to version 0.28.0 or later immediately.
Azərbaycanca: CVE-2026-56672: ComfyUI-nin 0.28.0-dan əvvəlki versiyalarında GET /userdata/{file} endpoint-i istifadəçi tərəfindən yüklənmiş HTML/SVG fayllarını düzgün kontent tipləri ilə təqdim edir. Bu, stored cross-site scripting (XSS) hücumlarına, API tokenlərinin, parametrlərin və iş axınlarının oğurlanmasına səbəb ola bilər. Təsirə məruz qalan sistemlər dərhal 0.28.0 və ya daha yuxarı versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ1
What risk does CVE-2026-56672 pose in ComfyUI?
CVE-2026-56672 allows stored XSS attacks in ComfyUI versions prior to 0.28.0 because user-uploaded HTML/SVG files are served with extension-derived content types. This can lead to theft of browser-stored API tokens, settings, and workflows.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.