CVE-2026-56670

ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpoint served uploaded SVG files inline because image/svg+xml and related XML content types were absent from the dangerous-content-type handling, allowing stored cross-site scripting in the ComfyUI origin. This issue is fixed in version 0.28.0.
Configurations

No configuration.

History

31 Jul 2026, 06:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-31 06:16

Updated : 2026-07-31 19:17


NVD link : CVE-2026-56670

Mitre link : CVE-2026-56670

CVE.ORG link : CVE-2026-56670


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')