Executive brief
AIDC-AI ComfyUI-Copilot, an AI-powered automation tool for ComfyUI, contains a security flaw that could allow unauthorized users to access other people's saved workflow data. By guessing or obtaining a specific version ID, an attacker can retrieve sensitive workflow configurations and session information that should be private. This could lead to the exposure of proprietary AI workflows or internal business logic.
Technical details
A resource injection vulnerability (CWE-99) exists in ComfyUI-Copilot up to version 2.0.28 within the `backend/controller/conversation_api.py` component. The application uses a bare integer `version_id` as the sole identifier for restoring workflow checkpoints without verifying the requester's session, user ID, or tenant context. A remote attacker with low privileges can exploit this by supplying a `version_id` belonging to another user to the `/api/restore-workflow-checkpoint` endpoint, leading to unauthorized retrieval of `workflow_data` and `workflow_data_ui`. While an exploit is publicly available, the attack complexity is considered high as it requires knowledge of valid version IDs. A fix has been proposed in Pull Request #150 but was not yet merged at the time of the advisory.
Affected products
- AIDC-AI ComfyUI-Copilot up to 2.0.28
Timeline
- 2026-05-27: patched: Pull request #150 submitted to fix scoping issues
- 2026-06-28: advisory: CVE published by VulDB/NVD