Description
ComfyUI before 0.30.0 fails to sanitize folder_name input in dataset save nodes, allowing attackers to write files to arbitrary paths outside the output directory. Attackers can load a crafted workflow that writes attacker-controlled content to arbitrary locations, enabling code execution through modified startup files or package initializers.
Published: 2026-09-16
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

ComfyUI versions prior to 0.30.0 fail to sanitize the folder_name parameter used in dataset save nodes, allowing an attacker to supply a crafted workflow that writes arbitrary files outside the intended output directory. The ability to write to system files can be leveraged to modify startup scripts or package initializers, thereby enabling the execution of attacker-controlled code.

Affected Systems

The affected product is Comfy-Org's ComfyUI, all releases before 0.30.0. No specific patch versions are listed, but versions earlier than 0.30.0 are known to be vulnerable.

Risk and Exploitability

The CVSS score of 8.5 indicates a high severity vulnerability, while the EPSS score of less than 1% suggests a low expected exploitation rate. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker must deliver a crafted workflow to a user running ComfyUI, which may require local access or the UI to be exposed over a network. Successful exploitation would enable the attacker to create or overwrite files on the host, potentially leading to remote code execution if system files or startup scripts are modified.

Generated by OpenCVE AI on September 18, 2026 at 05:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to ComfyUI version 0.30.0 or later, which includes input sanitization.
  • Restrict the file write permissions for the account running ComfyUI to prevent arbitrary file creation in protected directories.
  • Implement validation checks on the folder_name input to reject paths containing traversal sequences or disallowed characters.

Generated by OpenCVE AI on September 18, 2026 at 05:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description ComfyUI before 0.30.0 fails to sanitize folder_name input in dataset save nodes, allowing attackers to write files to arbitrary paths outside the output directory. Attackers can load a crafted workflow that writes attacker-controlled content to arbitrary locations, enabling code execution through modified startup files or package initializers.
Title ComfyUI before 0.30.0 Path Traversal via dataset save nodes
First Time appeared Comfy
Comfy comfyui
Weaknesses CWE-22
CPEs cpe:2.3:a:comfy:comfyui:*:*:*:*:*:*:*:*
Vendors & Products Comfy
Comfy comfyui
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T15:52:19.521Z

Reserved: 2026-09-16T19:55:03.228Z

Link: CVE-2026-92816

cve-icon Vulnrichment

Updated: 2026-09-21T15:52:16.378Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T21:17:31.647

Modified: 2026-09-22T20:53:07.383

Link: CVE-2026-92816

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:30:15Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')