comfyui-gateway
Warn
Audited by Socket on Aug 16, 2026
1 alert found:
SecuritySecurityreferences/integration.md
MEDIUMSecurityMEDIUM
references/integration.md
No direct malware/backdoor behavior is present in this fragment because it is configuration-only. However, it contains multiple plaintext secrets and credentialed connection strings (JWT/webhook/API keys, Redis/DB credentials, S3/MinIO access keys) and includes permissive wildcard inbound security settings in some modes. This represents a serious security risk driven by credential leakage and misconfiguration, and it warrants immediate remediation (secret management, removal from repo/artifacts, tightening allowlists, and ensuring auth material is never empty in any non-lab environment).
Confidence: 74%Severity: 88%
Audit Metadata