EXPOSURE ComfyUI
SEVERITY CRITICAL
PROBE GET :8188/system_stats
Is your ComfyUI exposed?
Open workflow API: arbitrary image jobs on your GPU, plus known RCE history.
Scan a host you own → Fix card
Why it matters
Anyone can upload and run workflows on your ComfyUI server — workflows can execute arbitrary code on the machine, and the open stats endpoint already shows attackers exactly what GPU hardware you have. Treat an internet-exposed ComfyUI as remote code execution waiting to happen.
How common is it?
A published population estimate for ComfyUI is still collecting. See the census methodology.
Counts are population-level, from third-party indexes and my own honeypots. I never scan the internet and this page makes no claim about any specific host.
Fix it
The full walkthrough lives on the fix card, kept current in one place: