CVE-2026-68771 – Unauthenticated RCE in ComfyUI via Insecure Deserialization in the LoadTrainingDataset Node
This story is from 2026-10-03. It is preserved in the archive; the latest stories are on the live feed.
Overview Field Value CVE ID CVE-2026-68771 Affected ComfyUI ≤ v0.23.0 Weakness CWE-502 (Deserialization of Untrusted Data) CVSS 3.1 9.8 (Critical) – AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Authentication required None Fix PR #14543, commit 94ee49b ComfyUI is a popular open-source node-graph GUI/backend…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-10-03 01:45 · DEV Community — AI
CVE-2026-68771 – Unauthenticated RCE in ComfyUI via Insecure Deserialization in the LoadTrainingDataset Node