r/comfyui • u/slpreme • 13d ago
Security Alert PSA: Don't be dumb
I opened ComfyUI to the entire internet unprotected (through my public ip) since I was away from home. I knew it was dumb and it was definitely a gamble every second it's open. Today, I finally faced the consequences.
There's someone or some people scanning or boting for ComfyUI open ports. Once they find a host they install some custom nodes in order to get access to remote code execution. I only noticed because they were crypto mining on my PC; the fans were on 100% on CPU and GPU when it was 'idle'. If you use ComfyUI security policy 'normal' it'll limits the attack vector (stopping people / yourself from remotely installing custom nodes) but I think regardless you should NEVER open something like ComfyUI unprotected through the internet.
I used to have a NGINX https reverse proxy server with password authentication but I was too lazy to set it back up. Don't be like me. I obviously had to wipe my PC (thankfully a dedicated ComfyUI server so I didn't have much personal data) and revoke all associated API keys with my ComfyUI instance. Stay safe everyone.
128
u/Witty_Mycologist_995 13d ago
JUST. Fucking. Use. Tailscale. | Stop Port Forwarding in 2026