Critical RCE Vulnerability in ComfyUI v0.23.0 (CVE-2026-68771)
Article Content
- •CVE-2026-68771 allows unauthenticated RCE in ComfyUI v0.23.0 via unsafe deserialization.
- •Attackers can upload malicious pickle files to execute arbitrary code as the ComfyUI process user.
- •A patch is available, and it is crucial to implement access controls on affected endpoints.
ComfyUI v0.23.0 has a critical remote code execution vulnerability (CVE-2026-68771) due to unsafe deserialization in the LoadTrainingDataset node. Unauthenticated remote attackers can exploit this flaw by uploading a malicious pickle file through the /upload/image endpoint and executing arbitrary Python code. The vulnerability allows attackers to control the ComfyUI process user and execute system commands. As of now, there is no evidence of exploitation in the wild, and no public proof-of-concept exists. A patch has been released, and users are advised to update to the latest version. Network-level access controls are recommended to restrict access to vulnerable endpoints. The CVSS base score for this vulnerability is 9.8, indicating its critical nature.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-68771 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…