CVE-2026-56672 | Comfy-Org ComfyUI up to 0.27.x User Data web.FileResponse path cross site scripting
A vulnerability was found in Comfy-Org ComfyUI up to 0.27.x and classified as problematic. This issue affects the function web.FileResponse of the component User Data Handler. Such manipulation of the argument path leads to cross site scripting.
This vulnerability is traded as CVE-2026-56672. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More