CVE-2026-108962 | storyicon comfyui_segment_anything up to ab6395596399d5048639cdab7e44ec9fae857a93 GroundingDINO Model Loading slconfig.py SLConfig._file2dict config code injection (Issue 114)

SecurityVulns

A vulnerability classified as critical was found in storyicon comfyui_segment_anything up to ab6395596399d5048639cdab7e44ec9fae857a93. Affected by this issue is the function SLConfig._file2dict of the file local_groundingdino/util/slconfig.py of the component GroundingDINO Model Loading. Such manipulation of the argument config leads to code injection.

This vulnerability is referenced as CVE-2026-108962. It is possible to launch the attack remotely. No exploit is available.

This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.

The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More