CVE-2026-68771
ComfyUI LoadTrainingDataset Unsafe Deserialization RCE
Halo Surface Signal: 3 out of 5 — possibly public-facing.
ComfyUI's LoadTrainingDataset node has an unsafe deserialization flaw. Unauthenticated remote attackers can exploit this by uploading a crafted pickle file, leading to arbitrary Python code execution. This could compromise the ComfyUI process. Assess if ComfyUI is deployed and reachable in your environment.