FOFA[verified]@fofabotDisclosure
The post announces a high‑severity RCE vulnerability (CVE‑2026‑68771) in ComfyUI v0.23.0, providing technical details and a FOFA query link, but it does not offer a PoC, exploit code, or patch information.
lee1981[verified]@lee1981bDisclosure
A critical unsafe‑deserialization vulnerability (CVE‑2026‑68771) in ComfyUI’s LoadTrainingDataset node allows unauthenticated RCE via malicious pickle shards, with high CVSS scores, but no patch or exploit details are disclosed.
Hugo | DevOps | Cybersecurity 🇱🇻[verified]@HugoValtersDisclosure
The post announces a critical RCE vulnerability (CVSS 9.8) in ComfyUI’s LoadTrainingDataset caused by unsafe deserialization and notes that no patch exists, advising users to avoid the /upload/image and /prompt endpoints.
Autumn Good@autumn_good_35Disclosure
The advisory announces CVE-2026-68771, detailing an unsafe deserialization flaw in ComfyUI v0.23.0 that permits unauthenticated remote attackers to execute arbitrary Python code via crafted pickle files, but provides no PoC, exploit code or patch details.
CVE@CVEnewDisclosure
The entry announces CVE-2026-68771, noting an unsafe deserialization vulnerability in ComfyUI v0.23.0 that permits unauthenticated remote code execution via the LoadTrainingDataset node.
ThreatAft@ThreatAftPatch
The tweet announces the ComfyUI CVE‑2026‑68771 vulnerability, highlights its severe impact, and urges users to apply the latest patch, without providing PoC or exploit details.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
CVE-2026-68771 is a newly disclosed vulnerability that allows remote code execution via unsafe deserialization in ComfyUI v0.23.0; no PoC, exploit, or patch details are included in the brief mention.