CVE-2026-6592: ComfyUI userdata Endpoint user_manager.py getuserdata cross site scripting
A vulnerability has been found in ComfyUI up to 0.13.0. Affected by this vulnerability is the function getuserdata of the file app/usermanager.py of the component userdata Endpoint. Such manipulation leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6592?
CVE-2026-6592 has a high severity due to its potential to allow cross-site scripting attacks.
How do I fix CVE-2026-6592?
To fix CVE-2026-6592, update ComfyUI to version 0.14.0 or later where the vulnerability is addressed.
What are the impacts of CVE-2026-6592?
CVE-2026-6592 can lead to unauthorized access and manipulation through cross-site scripting attacks.
Which versions of ComfyUI are affected by CVE-2026-6592?
CVE-2026-6592 affects all versions of ComfyUI up to and including 0.13.0.
Is there a workaround for CVE-2026-6592 until I can update?
Currently, there is no recommended workaround for CVE-2026-6592; updating to a fixed version is advised.