PT-2026-33658 · Comfyui · Comfyui

Eric-C

·

Published

2026-04-20

·

Updated

2026-04-20

·

CVE-2026-6589

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions ComfyUI versions prior to 0.13.1
Description A cross-site request forgery issue exists in the create origin only middleware() function within the server.py file. This flaw allows a remote attacker to initiate unauthorized requests by manipulating the application.
Recommendations Update to a version later than 0.13.0. As a temporary workaround, consider restricting access to the create origin only middleware() function until a patch is applied.

Exploit

Fix

CSRF

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-6589

Affected Products

Comfyui