Comfy-Org / Comfy-Org/ComfyUI-Manager

Possible security issue with how the manager handles Node Version Statuses & security scans.

Open
#2,632 0 comments 1 reaction 0 assignees View on GitHub
Dominant language
Python
Stars
16.1k
Forks
2.5k
Avg merge
5d 4h
Merged PRs (30d)
13

Description

During my research of this issue I also found that **people were still able to download my flagged custom node if they used the latest or nightly versions**. Also **if the security scan hadn't finished and it was still marked as NodeVersionStatusPending the version WOULD show up in ComfyUI Manager**, it would only disappear after the security scan finished and marked it as flagged. It seems like it sort of defeats the purpose of using `NodeVersionStatusActive` and the security scans if people can still download them through the manager. Perhaps a shield icon 🛡 next to versions that have been scanned and passed or approved could inform people of this?

Image

Pic with 1.12.2 is while the status was pending, pic without is AFTER the security scan when the version gets flagged as
NodeVersionStatusFlagged and needing review.

Image

So if the security scan hasn't finished people could be downloading malicious code and thinking it's been reviewed or scanned or is safe.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.