← what I check

EXPOSURE ComfyUI
SEVERITY CRITICAL
PROBE GET :8188/system_stats

CRITICAL

Is your ComfyUI exposed?

Open workflow API: arbitrary image jobs on your GPU, plus known RCE history.

Scan a host you own → Fix card

Why it matters

Anyone can upload and run workflows on your ComfyUI server — workflows can execute arbitrary code on the machine, and the open stats endpoint already shows attackers exactly what GPU hardware you have. Treat an internet-exposed ComfyUI as remote code execution waiting to happen.

How common is it?

A published population estimate for ComfyUI is still collecting. See the census methodology.

Counts are population-level, from third-party indexes and my own honeypots. I never scan the internet and this page makes no claim about any specific host.

Fix it

The full walkthrough lives on the fix card, kept current in one place:

Full fix card: comfyui-exposed →