T08 · Insecure Dependencies
- Location
scripts/setup.sh:68- Finding
Unpinned Remote Dependencies and Unverified Model Downloads
- Content
View full analysis
Vulnerability Details
File Location:
scripts/setup.sh:68-69,scripts/setup.sh:89-90,scripts/setup.sh:97-99, andscripts/setup.sh:144-165
Vulnerability Type: Supply-chain exposure through mutable dependencies and unverified artifacts
Risk Level: MediumVulnerable Code
bash git clone --depth 1 https://github.com/comfyanonymous/ComfyUI.git "$COMFY_DIR" || \ git clone --depth 1 https://ghfast.top/https://github.com/comfyanonymous/ComfyUI.git "$COMFY_DIR" || { err "ComfyUI clone failed; check the network and retry" exit 1 }bash pip install --upgrade pip setuptools wheel -q pip install torch torchvision torchaudio -q pip install -r "$COMFY_DIR/requirements.txt" -qbash git clone --depth 1 https://github.com/ltdrdata/ComfyUI-Manager.git "$COMFY_DIR/custom_nodes/ComfyUI-Manager" || \ git clone --depth 1 https://ghfast.top/https://github.com/ltdrdata/ComfyUI-Manager.git "$COMFY_DIR/custom_nodes/ComfyUI-Manager" || \ warn "ComfyUI-Manager installation failed; core functionality is unaffected"bash download() { local url="$1" output="$2" name="$3" if [ -s "$output" ]; then local size; size="$(du -h "$output" | awk '{print $1}')" warn "$name already exists ($size); skipping" return 0 fi log "Downloading $name..." curl -L -C - --progress-bar -o "$output" "$url" || \ curl -L -C - --progress-bar -o "$output" "$(echo "$url" | sed 's|https://huggingface.co|https://hf-mirror.com|')" || { warn "$name download failed; it can be downloaded manually later" rm -f "$output" return 0 } ok "$name download complete" } download \ "https://huggingface.co/stabilityai/stable-diffusion-xl-base-1.0/resolve/main/sd_xl_base_1.0.safetensors" \ "$MODELS_DIR/checkpoints/sd_xl_base_1.0.safetensors" \ "SDXL Base 1.0 (6.5GB)" download \ "https://huggingface.co/stabilityai/sdxl-vae/resolve/main/sdxl_vae.saf ...[truncated 2558 chars]- Remediation
View remediation
Remediation Suggestions
- Pin ComfyUI and ComfyUI-Manager to reviewed commit hashes or signed release tags. Clone first, verify the remote URL, and explicitly check out the approved commit.
- Maintain a dependency lockfile containing exact Python versions and hashes. Install with hash enforcement, such as
pip install --require-hashes. - Avoid silently falling back to third-party Git proxies or mirrors. If mirrors are necessary, document their trust model and require explicit user opt-in.
- Publish expected SHA-256 or stronger digests for every model artifact and reject any download that does not match.
- Download to a temporary file, verify the digest, and atomically move the artifact into the model directory only after successful verification.
- Run ComfyUI in a dedicated, unprivileged account or container with minimal filesystem mounts and restricted outbound network access.
- Separate the lightweight API client from the full installer so users with an existing ComfyUI deployment do not need to grant installation privileges.
