ComfyUI before 0.30.0 fails to sanitize folder_name input in dataset save nodes, allowing attackers to write files to arbitrary paths outside the output directory. Attackers can load a crafted workflow that writes attacker-controlled content to arbitrary locations, enabling code execution through modified startup files or package initializers.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ComfyUI before 0.30.0 fails to sanitize folder_name input in dataset save nodes, allowing attackers to write files to arbitrary paths outside the output directory. Attackers can load a crafted workflow that writes attacker-controlled content to arbitrary locations, enabling code execution through modified startup files or package initializers. | |
| Title | ComfyUI before 0.30.0 Path Traversal via dataset save nodes | |
| First Time appeared |
Comfy
Comfy comfyui |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:comfy:comfyui:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Comfy
Comfy comfyui |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T20:33:01.106Z
Reserved: 2026-09-16T19:55:03.228Z
Link: CVE-2026-92816
No data.
Status : Received
Published: 2026-09-16T21:17:31.647
Modified: 2026-09-16T21:17:31.647
Link: CVE-2026-92816
No data.
OpenCVE Enrichment
No data.
Weaknesses