Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6593

17
FAUCET Score

A Cross-Site Scripting (XSS) vulnerability (CVE-2026-6593) has been identified in ComfyUI versions up to 0.13.0, specifically within the View Endpoint functionality of the server.py file. The vulnerability allows attackers to manipulate the affected component to inject malicious scripts through the web interface. The vulnerability carries a CVSS score of 3.5 (LOW) with a network-based attack vector requiring low complexity and user interaction. The attack requires valid login credentials and user action to trigger, limiting the potential for widespread damage. The impact is restricted to integrity violations with no confidentiality or availability concerns. Exploitation status indicates active community attention with public exploit code available. However, the EPSS score of 0.00029 suggests minimal real-world exploitation likelihood relative to other vulnerabilities. The vendor was contacted early but did not respond to the disclosure, leaving this vulnerability unpatched in affected versions. Organizations running ComfyUI should consider updating to a version beyond 0.13.0 to mitigate this risk.

Impacted Technologies

VendorProductVersion(s)CPE
N/AComfyUI
0.1, 0.10, 0.11, 0.12, 0.13.0, 0.2, 0.3, 0.4, 0.5, 0.6, 0.7, 0.8, 0.9CNA affected

CVSS Data

CVSS version used by this source: 4.0

2.0LOW

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
PASSIVE
VS Confidentiality
NONE
VS Integrity
LOW
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.21%
Probability of exploitation in next 30 days
EPSS Percentile
10.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0021 is in the 23rd percentile among its peer group of 406 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

gist.github.com / YLChen-007/1d91fabb465284d7a974746f7e6cc5cc
vuldb.com / submit/791114
vuldb.com / vuln/358228
vuldb.com / vuln/358228/cti