What is CVE-2026-56673?
CVE-2026-56673 is a critical path traversal vulnerability in ComfyUI versions prior to 0.28.0, arising from the lack of a containment check when joining workflow-controlled annotated filenames to a base directory in the `folder_paths.get_annotated_filepath` and `exists_annotated_filepath` functions. This flaw allows an unauthenticated attacker to read arbitrary files on the server by manipulating filenames in a workflow. All affected users should immediately upgrade to ComfyUI 0.28.0 or later.
Azərbaycanca: CVE-2026-56673 ComfyUI-nin 0.28.0-dən əvvəlki versiyalarında aşkarlanmış kritik path traversal zəifliyidir. Bu zəiflik autentifikasiya olunmamış istifadəçilərə workflow vasitəsilə idarə olunan annotasiya fayl adlarını əsas direktoriyaya birləşdirərkən containment yoxlaması olmadığı üçün serverdə ixtiyari faylları oxumağa imkan verir. Təsirə məruz qalan sistemlər dərhal ComfyUI 0.28.0 və ya daha yuxarı versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
What versions of ComfyUI are affected by CVE-2026-56673?
ComfyUI versions prior to 0.28.0 are affected by this vulnerability.
What does CVE-2026-56673 allow an unauthenticated attacker to do?
This vulnerability allows an unauthenticated attacker to read arbitrary files on the server by manipulating filenames in a workflow.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.