A Cross-Site Scripting (XSS) vulnerability (CVE-2026-6593) has been identified in ComfyUI versions up to 0.13.0, specifically within the View Endpoint functionality of the server.py file. The vulnerability allows attackers to manipulate the affected component to inject malicious scripts through the web interface. The vulnerability carries a CVSS score of 3.5 (LOW) with a network-based attack vector requiring low complexity and user interaction. The attack requires valid login credentials and user action to trigger, limiting the potential for widespread damage. The impact is restricted to integrity violations with no confidentiality or availability concerns. Exploitation status indicates active community attention with public exploit code available. However, the EPSS score of 0.00029 suggests minimal real-world exploitation likelihood relative to other vulnerabilities. The vendor was contacted early but did not respond to the disclosure, leaving this vulnerability unpatched in affected versions. Organizations running ComfyUI should consider updating to a version beyond 0.13.0 to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | ComfyUI | 0.1, 0.10, 0.11, 0.12, 0.13.0, 0.2, 0.3, 0.4, 0.5, 0.6, 0.7, 0.8, 0.9CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.