Critical RCE Vulnerability in ComfyUI v0.23.0 (CVE-2026-68771)

Critical RCE Vulnerability in ComfyUI v0.23.0 (CVE-2026-68771)

First seen 2 Aug 2026, 08:52 UTC Feedlymallory.aiosv.dev 87% similarity 72.0

Article Content

Browse articles
ThreatCluster

ComfyUI v0.23.0 has a critical remote code execution vulnerability (CVE-2026-68771) due to unsafe deserialization in the LoadTrainingDataset node. Unauthenticated remote attackers can exploit this flaw by uploading a malicious pickle file through the /upload/image endpoint and executing arbitrary Python code. The vulnerability allows attackers to control the ComfyUI process user and execute system commands. As of now, there is no evidence of exploitation in the wild, and no public proof-of-concept exists. A patch has been released, and users are advised to update to the latest version. Network-level access controls are recommended to restrict access to vulnerable endpoints. The CVSS base score for this vulnerability is 9.8, indicating its critical nature.

Key Points: • CVE-2026-68771 allows unauthenticated RCE in ComfyUI v0.23.0 via unsafe deserialization. • Attackers can upload malicious pickle files to execute arbitrary code as the ComfyUI process user. • A patch is available, and it is crucial to implement access controls on affected endpoints.

ThreatCluster AI How this analysis works

Timeline

2026-07-31
CVE-2026-68771 published
The vulnerability in ComfyUI v0.23.0 was officially published, detailing the risks of unsafe deserialization.
osv.dev
2026-08-01
Security advisory released
A security advisory was issued, confirming the critical nature of the vulnerability with a CVSS score of 9.8 and recommending immediate updates.
Feedly
Recent
No evidence of exploitation found
As of the latest reports, there is no evidence of the vulnerability being actively exploited in the wild.
Feedly

Community

Browse all →

Tracked Entities in This Story