• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-68771: pre-auth remote code execution in Comfy-Org ComfyUI

Unauthenticated attackers can execute arbitrary code in ComfyUI by supplying a crafted pickle file that the application deserializes, leading to remote code execution (CVE-2026-68771). The flaw affects ComfyUI 0.23.0 and earlier. An attacker only needs network access to the application and the ability to upload a specially crafted shard_*.pkl file and then trigger a workflow that causes the server to load that file, which results in execution of attacker-controlled Python code as the ComfyUI process user.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.01148
CWE
CWE-502
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code is available, so treat this as high priority and apply the vendor's remediation or block the vulnerable upload/processing flow immediately.

What is CVE-2026-68771?

Unauthenticated attackers can execute arbitrary code in ComfyUI by supplying a crafted pickle file that the application deserializes, leading to remote code execution (CVE-2026-68771). The flaw affects ComfyUI 0.23.0 and earlier. An attacker only needs network access to the application and the ability to upload a specially crafted shard_*.pkl file and then trigger a workflow that causes the server to load that file, which results in execution of attacker-controlled Python code as the ComfyUI process user. The weakness is classified as CWE-502 (Deserialization of Untrusted Data).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Comfy-Org ComfyUI are affected?

BRANCHAFFECTEDFIXED
0.x0.23.0 and earlier

Is CVE-2026-68771 being exploited?

Public exploit code is available.

How to fix CVE-2026-68771

  1. Apply the vendor update or patch as soon as vendor guidance is published.
  2. If a patch is not yet deployed, restrict access to ComfyUI (block or firewall the service to trusted hosts only).
  3. Disable or restrict the upload endpoint and any automated processing that deserializes user-supplied pickle files.
  4. Monitor application logs and process activity for unexpected torch.load or pickle deserialization calls and suspicious command execution.

Frequently asked questions

Is CVE-2026-68771 being actively exploited?

Public exploit code for ComfyUI CVE-2026-68771 is available; the vulnerability is not listed in CISA's KEV catalog as of 2026-09-29.

Which ComfyUI versions are affected by CVE-2026-68771?

ComfyUI versions 0.23.0 and earlier are affected by CVE-2026-68771.

Is there a patch for CVE-2026-68771?

The vendor indicates a patch is available; fixed version numbers were not listed in the provided facts, so apply the vendor's published update guidance.

Does CVE-2026-68771 require authentication?

No — the vulnerability can be triggered by unauthenticated uploads and subsequent processing, allowing remote attackers to reach code execution without valid credentials.

References