CVE-2026-68771

🟠 Łataj w tym tygodniu

Niebezpieczna deserializacja w ComfyUI pozwala zdalnym atakującym na wykonanie dowolnego kodu Python.

CVSS
9.8
EPSS
0.6%
Exploit
none
Vendor
Opis źródłowy (NVD)

ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserialization. Attackers can upload a malicious shard_*.pkl file via the unauthenticated POST /upload/image endpoint and then queue a workflow graph via POST /prompt referencing the uploaded file, causing torch.load to deserialize the attacker-controlled pickle payload using __reduce__ and execute arbitrary commands as the ComfyUI process user.

deserialization Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS9.8
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.6%
Opublikowano (NVD)2026-07-31 22:17:03 UTC
Ostatnia modyfikacja (NVD)2026-08-03 18:16:41 UTC
Referencje