CVE-2026-13493
A flaw has been found in AIDC-AI ComfyUI-Copilot up to 2.0.28. This issue affects some unknown processing of the file backend/controller/conversation_api.py of the component Workflow Checkpoint Restore Handler. Executing a manipulation can lead to improper control of resource identifiers. The attack may be performed from remote. A high complexity level is associated with this attack. The exploitability is assessed as difficult. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance.
Scoring
- Severity
- LOW
- CVSS base score
- 3.1
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.36%
- CWE
- CWE-99
- Published
- 2026-06-28
- Last modified
- 2026-06-28
Affected products
- AIDC-AI ComfyUI-Copilot
- AIDC-AI ComfyUI-Copilot
- AIDC-AI ComfyUI-Copilot
- AIDC-AI ComfyUI-Copilot
- AIDC-AI ComfyUI-Copilot
- AIDC-AI ComfyUI-Copilot
- AIDC-AI ComfyUI-Copilot
- AIDC-AI ComfyUI-Copilot
Weakness type
Related vulnerabilities
- CVE-2026-81524 — Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C Driver
- CVE-2026-81521 — Cross-database write retargeting via unvalidated dotted database name in Client.BulkWrite in the MongoDB Go Driver
- CVE-2026-62910 — Microsoft Exchange Server Elevation of Privilege Vulnerability
- CVE-2026-15186 — macrozheng mall Portal Endpoint create resource injection
- CVE-2026-12207 — medkey-org medkey HTTP REST API PatientController.php actionGetPatientById resource injection
- CVE-2026-10624 — SourceCodester Human Resource Management Employee View detailview.php resource injection
- CVE-2026-10299 — code-projects Online Hospital Management System viewdoctortimings.php resource injection
- CVE-2026-10168 — OUSL-GROUP-BrinaryBrains School Student Management System Parents.php marks resource injection