CVE-2026-56671 | Comfy-Org ComfyUI up to 0.27.x Model Manager app/model_manager.py get_model_preview filename path traversal
A vulnerability classified as problematic has been found in Comfy-Org ComfyUI up to 0.27.x. Affected is the function get_model_preview of the file app/model_manager.py of the component Model Manager. Performing a manipulation of the argument filename results in path traversal.
This vulnerability is cataloged as CVE-2026-56671. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More