AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-19371

MEDIUM · CVSS 5.3 EPSS 0.14% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-09 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

A path traversal vulnerability exists in the copyFileSync function of the comfy_upload_image component in Nikolaibibo claude-comfyui-mcp 1.0.0, allowing local attackers to manipulate the image_path argument. This could lead to unauthorized file access on the system. Organizations using this software should prioritize remediation, especially if they have local access controls in place.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19371
Severity
MEDIUM
CVSS
5.3
EPSS
0.14%

Original NVD Description

A vulnerability was identified in Nikolaibibo claude-comfyui-mcp 1.0.0. Affected is the function copyFileSync of the file src/tools/utils.ts of the component comfy_upload_image. Such manipulation of the argument image_path leads to path traversal. An attack has to be approached locally. The project was informed of the problem early through an issue report but has not responded yet.