PT-2026-33687 · Comfyui · Comfyui
Eric-C
·
Published
2026-04-20
·
Updated
2026-04-21
·
CVE-2026-6593
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
ComfyUI versions prior to 0.13.0
Description
A flaw in the View Endpoint component within the
server.py file allows for remote cross site scripting. Cross site scripting is a type of security gap where malicious scripts are injected into otherwise trusted websites.Recommendations
Update to a version later than 0.13.0.
As a temporary workaround, restrict access to the View Endpoint component to minimize the risk of exploitation.
Exploit
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Comfyui