CVE-2026-68771 is a critical unauthenticated remote code execution (RCE) vulnerability affecting ComfyUI v0.23.0 and all earlier versions, stemming from unsafe pickle deserialization in the LoadTrainingDataset built-in node (CWE-502). With a CVSS 4.0 score of 9.3 (CRITICAL) and no authentication, user interaction, or special conditions required, any attacker with network access to an exposed ComfyUI instance can achieve full arbitrary code execution on the host server.
