PYPI · JULY 2026 · EARLY WARNING

ComfyUI v0.23.0 Unsafe Deserialization Vulnerability Under Investigation

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
CVE-2026-68771Severity: CRITICAL

ComfyUI v0.23.0 is reportedly affected by a critical deserialization vulnerability (CVE-2026-68771) that could allow unauthenticated remote attackers to execute arbitrary Python code.

What happened

An early warning has been issued regarding a critical deserialization vulnerability in ComfyUI v0.23.0. The vulnerability, tracked as CVE-2026-68771, is located in the LoadTrainingDataset node. It appears to allow unauthenticated remote attackers to execute arbitrary Python code by uploading a malicious shard_*.pkl file and triggering its deserialization. This could be achieved via the unauthenticated POST /upload/image endpoint and then queuing a workflow graph via POST /prompt referencing the uploaded file. The CVSS score for this vulnerability is 9.8, indicating a critical severity level. The incident is currently under investigation, and it is recommended to upgrade to a patched version of ComfyUI once available and review any custom workflows for potential exploitation. For more details, consult the primary sources.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If comfyui is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats