forked from Comfy-Org/ComfyUI
-
Notifications
You must be signed in to change notification settings - Fork 0
Pull requests: MassiveSecOrg/ComfyUI
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
[Aikido] Enforce 512M pixel-frame limit to mitigate unauthenticated DoS in video generation nodes
#18
opened Aug 27, 2026 by
aikido-staging-writecapable
Bot
Loading…
[Aikido] Prevent cross-user file exfiltration in OpenAI and Gemini workflow nodes
#17
opened Aug 27, 2026 by
aikido-staging-writecapable
Bot
Loading…
[Aikido] Require cryptographic tokens for multi-user authentication in app/user_manager.py
#16
opened Aug 27, 2026 by
aikido-staging-writecapable
Bot
Loading…
[Aikido] Fix unauthenticated cross-user job disclosure in API endpoints
#14
opened Aug 27, 2026 by
aikido-staging-writecapable
Bot
Loading…
[Aikido] Prevent cross-instance asset access via path validation in asset_management.py
#15
opened Aug 27, 2026 by
aikido-staging-writecapable
Bot
Loading…
[Aikido] Prevent cross-tenant asset exposure by threading owner_id through prompt execution chain
#13
opened Aug 27, 2026 by
aikido-staging-writecapable
Bot
Loading…
[Aikido] Validate client_id as string or null in POST /prompt to prevent DoS
#12
opened Aug 27, 2026 by
aikido-staging-writecapable
Bot
Loading…
[Aikido] Add opt-in API key authentication middleware for control endpoints
#11
opened Aug 27, 2026 by
aikido-staging-writecapable
Bot
Loading…
[Aikido] Require GPG signatures and commit hash verification in Windows updater
#10
opened Aug 27, 2026 by
aikido-staging-writecapable
Bot
Loading…
[Aikido] Enforce owner_id validation for ownerless asset references in mutations
#9
opened Aug 27, 2026 by
aikido-staging-writecapable
Bot
Loading…
[Aikido] Remove users registry from /users endpoint in multi-user mode
#8
opened Aug 27, 2026 by
aikido-staging-writecapable
Bot
Loading…
[Aikido] Prevent custom node whitelist bypass via basename collision attacks
#7
opened Aug 27, 2026 by
aikido-staging-writecapable
Bot
Loading…
[Aikido] Enforce pixel budget limit in EmptyImage to prevent DoS via unbounded tensor dimensions
#6
opened Aug 27, 2026 by
aikido-staging-writecapable
Bot
Loading…
[Aikido] Restrict asset download path resolution to owned or ownerless references
#5
opened Aug 27, 2026 by
aikido-staging-writecapable
Bot
Loading…
[Aikido] Prevent excessive tensor allocation in ImagePadForOutpaint via dimension validation
#4
opened Aug 27, 2026 by
aikido-staging-writecapable
Bot
Loading…
[Aikido] Fix unrestricted format string traversal vulnerability in StringFormat node
#3
opened Aug 27, 2026 by
aikido-staging-writecapable
Bot
Loading…
[Aikido] Enforce PyTorch minimum version 2.7.0 to mitigate deserialization vulnerability
#2
opened Aug 27, 2026 by
aikido-staging-writecapable
Bot
Loading…
[Aikido] Fix path traversal vulnerability in SaveText format parameter validation
#1
opened Aug 27, 2026 by
aikido-staging-writecapable
Bot
Loading…
ProTip!
Mix and match filters to narrow down what you’re looking for.