VYPR

claude-comfyui-mcp

by Nikolaibibo

CVEs (1)

  • CVE-2026-19371MedAug 9, 2026
    risk 0.34cvss 5.3epss

    A vulnerability was identified in Nikolaibibo claude-comfyui-mcp 1.0.0. Affected is the function copyFileSync of the file src/tools/utils.ts of the component comfy_upload_image. Such manipulation of the argument image_path leads to path traversal. An attack has to be approached…