Description
ComfyUI before 0.30.0 fails to sanitize folder_name input in dataset save nodes, allowing attackers to write files to arbitrary paths outside the output directory. Attackers can load a crafted workflow that writes attacker-controlled content to arbitrary locations, enabling code execution through modified startup files or package initializers.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 16 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ComfyUI before 0.30.0 fails to sanitize folder_name input in dataset save nodes, allowing attackers to write files to arbitrary paths outside the output directory. Attackers can load a crafted workflow that writes attacker-controlled content to arbitrary locations, enabling code execution through modified startup files or package initializers. | |
| Title | ComfyUI before 0.30.0 Path Traversal via dataset save nodes | |
| First Time appeared |
Comfy
Comfy comfyui |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:comfy:comfyui:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Comfy
Comfy comfyui |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T20:33:01.106Z
Reserved: 2026-09-16T19:55:03.228Z
Link: CVE-2026-92816
No data.
Status : Received
Published: 2026-09-16T21:17:31.647
Modified: 2026-09-16T21:17:31.647
Link: CVE-2026-92816
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')