PT-2026-33659 · Comfyui · Comfyui

Eric-C

·

Published

2026-04-20

·

Updated

2026-04-20

·

CVE-2026-6590

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions ComfyUI versions prior to 0.13.0
Description A path traversal issue exists in the Model Preview Endpoint within the get model preview() function of the app/model manager.py file. This flaw allows a remote attacker to manipulate file paths to access unauthorized directories.
Recommendations Update to a version later than 0.13.0. As a temporary workaround, restrict access to the get model preview() function until a patch is applied.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6590

Affected Products

Comfyui