A vulnerability classified as critical was found in Nikolaibibo claude-comfyui-mcp 1.0.0. Affected is the function
copyFileSync of the file src/tools/utils.ts of the component comfy_upload_image. Such manipulation of the argument image_path leads to path traversal.
This vulnerability is traded as CVE-2026-19371. An attack has to be approached locally. Furthermore, there is an exploit available.
The project was informed of the problem early through an issue report but has not responded yet.