Guides

How to Lock Down a Production ComfyUI Instance: A Studio Security Checklist

ยท RenderBob team

If ComfyUI is in your production pipeline and you handle client material, treat it like production software. Work this checklist.

Layered security controls protect a production node graph, GPU core, storage, access paths, and client media.

If ComfyUI is in your production pipeline and you handle client material, treat it like production software. Work this checklist.

1. Never expose an instance to the open internet

The 2026 cryptomining botnet found its victims by scanning for publicly reachable ComfyUI instances and exploiting unauthenticated ones. A production instance should sit behind a VPN or on an internal network, never on a public IP with an open port. This single step removes the most common attack path.

2. Patch ComfyUI-Manager and keep it current

The botnet exploited a Manager vulnerability fixed in v3.38 (CVE-2025-67303). Pin a known-good, patched Manager version across every machine and update deliberately, not never and not blindly.

3. Vet custom nodes before they're installed, centrally

Don't let each artist install whatever they find. Maintain an approved list, and scan candidate nodes with a security scanner before adding them. Registry standards now forbid obfuscated code and runtime subprocess installs. Treat any node breaking those rules as disqualified.

4. Treat downloaded workflow JSON as untrusted input

A shared workflow can exploit vulnerable nodes on import. Review workflows from outside your studio before loading them on a production instance, the same way you'd review any third-party code.

5. Segment the network

Production render machines should not sit on the same flat network as everything else. If a node is compromised, segmentation limits how far it reaches, especially where client IP is present.

6. Run sensitive work offline

For NDA-bound client material, an air-gapped or tightly controlled offline instance with a pre-vetted node set removes the exfiltration path. Nothing can be stolen if nothing can phone home.

7. Practice credential hygiene

No single-holder credentials, documented access paths, and no long-lived secrets sitting on artist workstations. Infostealers target exactly this.

8. Monitor and log

Know what's running. Unexplained GPU utilisation was how studios discovered the cryptomining infection in the first place.

This is the ordinary discipline of running third-party plugin software in production, the same discipline any studio would apply to a render manager or asset system. ComfyUI grew up as a solo creative instrument and got adopted into production faster than its security practices did. Closing that gap is most of what a client's security reviewer is actually asking about.

More from the blog

  • A Risk Ladder for AI in Documentary

    Screenweaver's 8 October guide ranks five documentary uses of AI by risk, from archive restoration to a synthetic face, and pairs them with EU disclosure rules now in force.

  • The B-Roll Gap: Generated, Selected, or Shot

    Every cut eventually needs a shot that does not exist. AI can generate it or search a library for it, and stock libraries are answering with different rules. Here is how to choose.

All posts