Timeline / Generative AI
ComfyUI security: reviewing nodes and protecting your work
A workflow asks you to install three missing nodes. Before accepting, find out which code will enter your machine and which files it will be able to reach.
ComfyUI brings models and tools together in visual workflows. Its flexibility comes with a practical consideration: adding a custom node installs software. An impressive example image tells you little about whether that software is safe.
For a studio, the useful question is what an installation could reach if something went wrong: client folders, browser sessions, service keys or shared files.
Before installing a custom node
Find the original repository, check who maintains it and review its dependencies and security notices. Stars and download counts can help you discover a tool; they cannot replace a review.
- Record the repository and the version or commit you plan to test.
- Check installation instructions and new dependencies.
- Keep client material and credentials out of the test.
- Preserve a working environment before updating it.
If your team cannot review the code, restrict what the installation can read and change. A Python virtual environment separates dependencies; it is not a security boundary against malicious code.
Set up a useful test environment
Separate node testing from the environment used for deliveries. Keep a small workflow with sample files and check it after each change.
That separation needs to include permissions. Another folder with access to the same client files and credentials does not solve the problem. A dedicated machine or isolated environment still needs appropriate network, shared-folder and secret configuration.
Document how to return to the previous version. Recording core, Manager, nodes and dependencies makes a delivery easier to reproduce and a regression easier to trace.
What security_level controls
ComfyUI-Manager provides four settings for restricting certain operations:
| Setting | Documented restriction |
|---|---|
| strong | Blocks features classified as high and medium risk |
| normal | Blocks high-risk features |
| normal- | Applies the high-risk restriction according to the listening address |
| weak | Allows all features |
These settings govern Manager operations. They neither prove a node is trustworthy nor run it in a sandbox. Check the official policy and config.ini location for your version.
Sharing ComfyUI with a team
The --listen option changes where the server listens. Actual exposure depends on its address, firewall, routing and any intermediate proxy. Enabling it alone does not mean the machine is reachable from the public Internet.
Before sharing an instance, decide who needs access and from which network. Restrict allowed connections, protect access and avoid directly exposing a working installation without controls. Test from another machine so you know the effective access matches the intended configuration.
Lessons from documented incidents
Snyk reported vulnerabilities in Manager and several node packages. PyPI later analysed compromised versions of ultralytics, a dependency used by different projects. These illustrate separate entry points: an extension and the software it installs.
In January 2026, Tencent published CVE-2025-67303, affecting Manager versions before 3.38. The advisory describes a vulnerability that can permit unauthenticated remote code execution. Follow the advisory and remediation instructions. A minimum version fixing one vulnerability is not a guarantee that the installation addresses every subsequent issue.
During an update, follow the relevant migration guide and review the configuration and old snapshots you restore. Avoid automatically restoring a state whose provenance is unknown.
A short check before production
Establish four things before adopting a workflow: approved versions, accessible files, authorised users and a recovery procedure. Revisit them when a relevant node or dependency changes.
For a related assessment of automated workflows, see our guide to AI agent reliability. If you need to integrate a generative workflow into a studio, tell us about your environment and material.
Sources
Reviewed on 20 September 2026.
- ComfyUI: Manager security policy.
- Snyk Labs: custom-node vulnerabilities.
- PyPI: ultralytics attack analysis.
- Tencent Xuanwu Lab: CVE-2025-67303.
Checked on September 20, 2026