Home

Description

A vulnerability has been found in ComfyUI up to 0.13.0. Affected by this vulnerability is the function getuserdata of the file app/user_manager.py of the component userdata Endpoint. Such manipulation leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED Reserved 2026-04-19 | Published 2026-04-20 | Updated 2026-04-20 | Assigner VulDB




MEDIUM: 5.1CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
LOW: 3.5CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R
LOW: 3.5CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R
4.0AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR

Problem types

Cross Site Scripting

Code Injection

Timeline

2026-04-19:Advisory disclosed
2026-04-19:VulDB entry created
2026-04-19:VulDB entry last update

Credits

Eric-c (VulDB User) reporter

VulDB CNA Team coordinator

References

vuldb.com/vuln/358227 (VDB-358227 | ComfyUI userdata Endpoint user_manager.py getuserdata cross site scripting) vdb-entry technical-description

vuldb.com/vuln/358227/cti (VDB-358227 | CTI Indicators (IOB, IOC, TTP, IOA)) signature permissions-required

vuldb.com/submit/791113 (Submit #791113 | comfyanonymous ComfyUI <= 0.13.0 (commit 88e63705) Cross-Site Scripting (CWE-79)) third-party-advisory

gist.github.com/YLChen-007/50f0cdc5e3f7b737ce99c783e487ca0d exploit

cve.org (CVE-2026-6592)

nvd.nist.gov (CVE-2026-6592)

Download JSON