Tech

CVE-2026-56671 ComfyUI: Path traversal in /experiment/models/preview allows arbitrary image file read

vulners.comJuly 31, 2026

ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, getmodelpreview in app/modelmanager.py joins an unrestricted filename route capture to a selected model directory without a containment check, allowing an unauthenticated remote attacker to use t...

Read full story at vulners.com