A vulnerability has been found in Comfy-Org ComfyUI up to 0.27.x and classified as problematic. This vulnerability affects the function
folder_paths.get_annotated_filepath/exists_annotated_filepath of the file folder_paths.py of the component LoadImage. This manipulation causes path traversal.
This vulnerability appears as CVE-2026-56673. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.