CVE-2026-56673 | Comfy-Org ComfyUI up to 0.27.x LoadImage folder_paths.py path traversal
A vulnerability has been found in Comfy-Org ComfyUI up to 0.27.x and classified as problematic. This vulnerability affects the function folder_paths.get_annotated_filepath/exists_annotated_filepath of the file folder_paths.py of the component LoadImage. This manipulation causes path traversal.
This vulnerability appears as CVE-2026-56673. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.VulDB Recent EntriesRead More