ComfyUI users need to patch immediately. CVE-2026-68771, rated a critical 9.8 on the CVSS 3.1 scale, allows unauthenticated attackers to achieve Remote Code Execution (RCE) on ComfyUI instances up to version v0.23.0. The vulnerability stems from a dangerous combination of insecure deserialization and lack of input validation in the LoadTrainingDataset node, effectively handing over server control to anyone who can hit the network endpoint.
The Vulnerability Chain
The issue isn't a single bug but a chain of two independent flaws. First, the /upload/image endpoint accepts arbitrary files without checking content type or extension, allowing attackers to upload malicious .pkl files directly to the server's output directory. Second, the LoadTrainingDataset node uses torch.load() without the weights_only=True safety flag. Because PyTorch's torch.load() relies on Python's pickle module, it executes the REDUCE opcode during deserialization, which can invoke arbitrary system commands if the file contains a crafted __reduce__ method.
Why It Matters for Builders
For developers running ComfyUI on exposed servers, this is a nightmare scenario. The attack requires no authentication. An attacker simply uploads a crafted pickle file named shard_0001.pkl to a specific subfolder, then triggers a workflow that points the LoadTrainingDataset node to that same folder. The server then deserializes the file, executing the attacker's code with the privileges of the ComfyUI process. This bypasses the typical assumption that file uploads are inert data.
The Fix and Scope
The official fix landed in PR #14543, commit 94ee49b. The patch is minimal: it adds weights_only=True to the torch.load() call in comfy_extras/nodes_dataset.py. This flag restricts deserialization to safe types like tensors and basic containers, blocking the execution of arbitrary Python objects. Notably, the fix does not address the underlying lack of validation in the upload endpoint itself, meaning /upload/image still allows writing arbitrary files to disk. However, it breaks the chain by preventing those files from being executed as code.
Key Takeaways
- ComfyUI versions โค v0.23.0 are vulnerable to unauthenticated RCE via CVE-2026-68771.
- The attack exploits CWE-502 (Deserialization of Untrusted Data) in the LoadTrainingDataset node.
- Patching requires updating to the commit that enables weights_only=True in torch.load().
- The upload endpoint remains unvalidated, so defense-in-depth via network isolation is still recommended.
The Bottom Line
Never trust a file upload endpoint that doesn't validate content, and never let pickle decide what code runs on your server. This CVE is a stark reminder that 'just a data file' is a dangerous assumption in Python ecosystems.