OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-92816 (CVSS 8.5)

NVD · officialPublished Sep 16, 2026Risk 37/100EPSS 0.2%

ComfyUI before 0.30.0 fails to sanitize folder_name input in dataset save nodes, allowing attackers to write files to arbitrary paths outside the output directory. Attackers can load a crafted workflow that writes attacker-controlled content to arbitrary locations, enabling code execution through modified startup files or package initializers.

CVSS
8.5
AV:LocalAC:LowPR:NoneUI:Passive

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source