CVE-2026-68771 | Comfy-Org ComfyUI up to 0.23.0 LoadTrainingDataset Node /upload/image torch.load deserialization

SecurityVulns

A vulnerability categorized as critical has been discovered in Comfy-Org ComfyUI up to 0.23.0. Impacted is the function torch.load of the file /upload/image of the component LoadTrainingDataset Node. Such manipulation leads to deserialization.

This vulnerability is listed as CVE-2026-68771. The attack may be performed from remote. There is no available exploit.VulDB Recent EntriesRead More