comfy.utils.load_safetensors() (used by VAELoader and other loaders when
the DynamicVRAM/aimdo backend is active) never validated that the
memory-mapped file actually contained as many bytes as the safetensors
header declared. When a .safetensors file was truncated -- e.g. still
downloading, or an interrupted/partial download -- Python's silent slice
clipping handed torch.frombuffer() a short buffer, producing the
inscrutable low-level error:
ValueError: buffer length (N bytes) after offset (0 bytes) must be
a multiple of element size (4)
instead of the clear "corrupt/incomplete file" message already produced
by the sibling (non-aimdo) safetensors.safe_open() code path for the same
underlying condition.
This adds an explicit bounds check against the header's declared data
size and raises the same friendly, actionable ValueError used elsewhere
in load_torch_file() for corrupt/incomplete files.
Fixes#14784 (reported by xnx20050723-lgtm).
Since comfy_aimdo's ModelMMAP requires a compiled, GPU-platform-specific
native backend unavailable in CI/dev environments without a real GPU, the
added test monkeypatches ModelMMAP with a fake backed by a real,
synthetic, truncated safetensors buffer, letting
comfy.utils.load_safetensors() itself be exercised deterministically.
Verified revert-proof: reverting the fix reproduces the exact reported
error string, `buffer length (37 bytes) after offset (0 bytes) must be a
multiple of element size (4)`.
* security: fix five vulnerabilities (GHSA-779p-m5rp-r4h4)
- CVE-2026-56670: force download of SVG/XML responses on /view to prevent stored XSS
- CVE-2026-56671: contain /experiment/models/preview reads within the model folder
- CVE-2026-56672: stop inline rendering of uploaded /userdata/{file} content
- CVE-2026-56673: prevent path traversal in get_annotated_filepath (LoadImage /prompt input)
- CVE-2026-56674: reject opaque/null Origin to close the CSRF middleware bypass
Adds regression tests under tests-unit/security_test/ covering all five.
* security: address review feedback on GHSA-779p fixes
- Fix Windows CI failure in test_get_annotated_filepath: compare against
os.path.abspath(...) to match the intentional abspath normalization added
by the traversal hardening (abspath prepends the drive letter on Windows).
- origin_check: narrow the bare `except:` in is_loopback() to ValueError so
genuine interrupts aren't swallowed (review nit).
- origin_check: guard .port access in is_cross_origin_forbidden() so a
malformed/out-of-range port (e.g. Origin: http://127.0.0.1:99999) fails
closed with a 403 instead of surfacing an uncaught 500 in the middleware.
- server /view: escape backslash/quote in the Content-Disposition filename
(RFC 6266 quoted-string) so a filename containing a double quote can't
malform the response header.
* security: address CodeRabbit review feedback on GHSA-779p tests
- test #3: guard the symlink-escape test with a try/except skip so it no
longer errors on Windows CI where os.symlink needs elevated privileges /
Developer Mode (mirrors the guard in the sibling test #2).
- test #5: refresh the stale module docstring to describe the actual /view
gating (view_image closure calling folder_paths.is_dangerous_content_type,
the normalising check) instead of the bypassable raw set-membership test.
* revert(security): drop CVE-2026-56674 Origin: null CSRF change
Per maintainer review, the reported CSRF is already mitigated by the pre-existing
Sec-Fetch-Site: cross-site check for current browsers, and the null-origin
rejection risked breaking legitimate sandboxed-iframe embeds. Restores
origin_only_middleware and is_loopback in server.py to their prior state
(the Sec-Fetch-Site check is retained) and removes utils/origin_check.py and its
regression test. The other four GHSA-779p fixes are unaffected.
All past 30 min of comtts are done on the top of Mt Fuji
By Comfy, Robin, and Yoland
All other comfy org members died on the way
Introduced unit tests to verify the correctness of various folder path
utility functions such as `get_directory_by_type`, `annotated_filepath`,
and `recursive_search` among others. These tests cover scenarios
including directory retrieval, filepath annotation, recursive file
searches, and filtering files by extensions, enhancing the robustness
and reliability of the codebase.