Security: Comfy-Org/ComfyUI_frontend
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Stored DOM-XSS via unescaped node property names rendered with innerHTML in the node Properties dialogGHSA-j6xv-rx8r-mh6j published
Aug 18, 2026 by christian-byrneHigh -
Stored DOM-XSS via unescaped group-node and subgraph names rendered with v-html in node searchGHSA-2gr5-vw2p-2hcf published
Aug 18, 2026 by christian-byrneHigh -
Cloud "Open Image" can cause same-origin XSS when opening attacker-controlled contentGHSA-8xxc-66vh-2pf3 published
Aug 18, 2026 by christian-byrneHigh
Learn more about advisories related to Comfy-Org/ComfyUI_frontend in the GitHub Advisory Database