CVE-2026-6589 is a cross-site request forgery (CSRF) vulnerability in ComfyUI versions up to 0.13.0, specifically within the create_origin_only_middleware function of server.py. This flaw allows attackers to perform unauthorized actions on behalf of authenticated users through malicious web requests. The vulnerability has a CVSS score of 4.3 (Medium) with a network-based attack vector requiring minimal complexity and user interaction. While the impact on confidentiality and availability is negligible, the integrity impact is limited, making this a low-to-moderate risk vulnerability in isolation. The vulnerability has been publicly disclosed, and exploit code is available for potential misuse, though current exploitation activity appears minimal as indicated by the low EPSS score of 0.00015. Despite early vendor notification, the developer provided no response, and the vulnerability remains listed on the active KEV Catalog, warranting attention from organizations using affected ComfyUI versions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | ComfyUI | 0.1, 0.10, 0.11, 0.12, 0.13.0, 0.2, 0.3, 0.4, 0.5, 0.6, 0.7, 0.8, 0.9CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.