What is CVE-2026-68771?
ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node. This vulnerability allows unauthenticated remote attackers to execute arbitrary Python code by uploading a malicious pickle file. ComfyUI users should immediately disable the component or upgrade to the latest patched version.
Azərbaycanca: ComfyUI v0.23.0 proqramında yerləşən LoadTrainingDataset node-da təhlükəli deserialization zəifliyi aşkar edilib. Bu, uzaqdan autentifikasiya olunmamış hücumçulara xüsusi hazırlanmış pickle faylı yükləyərək ixtiyari Python kodu icra etməyə imkan verir. ComfyUI istifadəçiləri dərhal komponenti deaktiv etməli və ya ən son təhlükəsizlik yeniləməsinə keçməlidir.
Related CVEs
link basis: same weakness class CWE-502
FAQ2
What vulnerability has been discovered in ComfyUI v0.23.0?
An unsafe deserialization vulnerability has been discovered in the LoadTrainingDataset node of ComfyUI v0.23.0.
How can an attacker execute arbitrary code through this vulnerability?
An unauthenticated remote attacker can execute arbitrary Python code by uploading a malicious pickle file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.