PT-2026-33687 · Comfyui · Comfyui

Eric-C

·

Published

2026-04-20

·

Updated

2026-04-21

·

CVE-2026-6593

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions ComfyUI versions prior to 0.13.0
Description A flaw in the View Endpoint component within the server.py file allows for remote cross site scripting. Cross site scripting is a type of security gap where malicious scripts are injected into otherwise trusted websites.
Recommendations Update to a version later than 0.13.0. As a temporary workaround, restrict access to the View Endpoint component to minimize the risk of exploitation.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-6593

Affected Products

Comfyui