CVE-2026-68771: ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by up
ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserialization. Attackers can upload a malicious shard_*.pkl file via the unauthenticated POST /upload/image endpoint and then queue a workflow graph via POST /prompt referencing the uploaded file, causing torch.load to deserialize the attacker-controlled pickle payload using reduce and execute arbitrary commands as the ComfyUI process user.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-68771
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-68771 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for ComfyUI
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-56673: ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Pr…nvd · 2026-07-31
- highCVE-2026-56672: ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/…nvd · 2026-07-31
- highCVE-2026-56671: ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior …nvd · 2026-07-31
- highCVE-2026-56670: ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior …nvd · 2026-07-31
- lowCVE-2026-13493: A flaw has been found in AIDC-AI ComfyUI-Copilot up to 2.0.28. This issue affects some unknown…nvd · 2026-06-28
More from NVD Recent CVEs
- mediumCVE-2026-67355: guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the …2026-08-01
- mediumCVE-2026-67354: guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in Re…2026-08-01
- mediumCVE-2026-67353: guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the Cook…2026-08-01
- highCVE-2026-67352: luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_…2026-08-01
- mediumCVE-2026-67344: ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYP…2026-08-01