ComfyUI Manager is a community-developed extension for the ComfyUI node-based image and video generation interface that provides an integrated package management system for discovering, installing, updating, and disabling custom nodes and their Python dependencies. It maintains a curated registry of available custom node repositories and model assets, resolves dependency conflicts, and enables reproducible workflow sharing by exporting workflow snapshots that encode all required node specifications. The extension also integrates model management features for downloading checkpoint, LoRA, VAE, and ControlNet files from external repositories, and performs missing-node detection when importing workflows created on other machines. As the de facto package manager for the ComfyUI ecosystem, it substantially lowers the barrier to extending the platform with community-developed preprocessing, sampling, and post-processing nodes.

Semantic Classification

Content

Compositional Relationships (Components)

SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:hasPart ai:CustomNodeRegistry))
SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:hasPart ai:MissingNodeDetection))
SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:hasPart ai:ModelDownloader))
SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:hasPart ai:SnapshotManagement))
SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:hasPart ai:UpdateManager))
SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:hasPart ai:DisableEnableToggle))
SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:hasPart ai:DependencyConflictResolver))
SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:hasPart ai:ModelHashVerifier))

Dependency Relationships

SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:requires ai:ComfyUI))
SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:requires ai:Git))
SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:requires ai:Python))
SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:requires ai:PythonPackageManagement))
SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:dependsOn ai:GPUCompute))
SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:dependsOn ai:PyTorch))
SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:dependsOn ai:HuggingFace))
SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:dependsOn ai:DiffusionModel))

Capability Relationships

SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:enables ai:WorkflowPortability))
SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:enables ai:ReproducibleMLPipelines))
SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:enables ai:CommunityExtensionEcosystem))
SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:enables ai:ImageGeneration))
SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:enables ai:VideoGeneration))
SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:enables ai:ContentCreationPipeline))

Implementation Relationships

SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:implements ai:WorkflowAutomation))
SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:implements ai:NodeBasedProgramming))
SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:implements ai:PackageManagerPattern))
SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:implements ai:DependencyResolution))

Reduction Relationships

SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:reducesTo ai:ComfyUI))
SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:reducesTo ai:PythonPackageManagement))
SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:reducesTo ai:GitRepositoryManagement))
SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:reducesTo ai:CustomNodeRegistry))
SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:reducesTo ai:WorkflowPortability))

Additional Axioms — Contrast and Standards

SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:contrastsWith ai:AUTOMATIC1111WebUI))
SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:contrastsWith ai:pip))
SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:standardizedBy ai:ComfyOrgGitHubOrganisation))
SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:supports ai:AnimateDiff))
SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:supports ai:Flux1))
SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:supports ai:ESRGANUpscaling))
SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:supports ai:FaceRestoration))
SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:uses ai:CivitAI))
SubClassOf(ai:ComfyUIManager
  ObjectSomeValuesFrom(ai:uses ai:uvPackageManager))

About

The ComfyUI Manager extension is best understood through its role in solving the custom node installation problem that would otherwise have severely constrained the ComfyUI ecosystem’s growth. When ComfyUI launched in January 2023 it exposed a clean extension mechanism: any Python module placed in the custom_nodes/ directory whose __init__.py registered entries in NODE_CLASS_MAPPINGS would be available as node types in the next server restart. This mechanism made adding new capabilities trivially easy for developers but correspondingly painful for users: each new capability was a separate Git repository requiring manual clone, a separate Python virtual environment concern requiring manual dependency install, and a separate compatibility matrix to maintain across ComfyUI core updates. Within weeks of ComfyUI’s release, the community had published dozens of custom node packages; within months, the count was in the hundreds. The AUTOMATIC1111 Stable Diffusion WebUI had faced an analogous extension problem and addressed it with a built-in extensions tab backed by a community-maintained index. ComfyUI Manager implemented the same solution for ComfyUI, establishing the registry-clone-pip pattern that became the universal installation method for the next two years.

ComfyUI Manager fills a critical infrastructure gap that emerged immediately upon the ComfyUI ecosystem’s explosive growth after January 2023. While ComfyUI itself provided a highly composable, graph-based interface for constructing Stable Diffusion and broader Diffusion Model pipelines, the practical value of the platform depended entirely on the availability and correct installation of community-authored custom node packages — each a Python module registered within ComfyUI’s extension loading system. Before the ltdrdata 2023 ComfyUI-Manager extension existed, users were required to manually clone individual repositories into the custom_nodes/ directory, resolve Python dependency conflicts through the command line, and identify missing nodes in shared ComfyUI Workflows by manually parsing workflow JSON files to find class_type references. ComfyUI Manager automated the entire process: a centralised JSON registry of community packages (maintained in the ltdrdata/ComfyUI-Manager GitHub repository and now also at the official Comfy Node Registry at registry.comfy.org) became the catalogue; Git clone became the installation mechanism; pip (and later the faster uv Package Manager) became the dependency resolution engine; and a browser-accessible management panel became the user interface for all of these operations. The result established a community norm for node discovery and made ComfyUI Workflows genuinely portable: a workflow JSON exported from one machine could be imported on another, and ComfyUI Manager would identify which custom nodes were absent and guide installation of the missing packages.

The scale of the ecosystem that ComfyUI Manager enabled is significant. By 2025, the custom node registry listed over one thousand packages spanning every conceivable Generative AI capability: ControlNet preprocessors for depth, pose, edge, and normal map conditioning; LoRA loaders and stacking utilities; IP-Adapter nodes for reference image injection; AnimateDiff and ComfyUI-AnimateDiff-Evolved for video generation; upscaling nodes wrapping ESRGAN and Real-ESRGAN; Face Restoration nodes wrapping GFPGAN and CodeFormer; LLM API connector nodes for prompt generation via GPT-4 and Claude; 3D mesh generation nodes via TripoSR and Zero123; audio generation nodes via MusicGen; and entire research paper implementations published as ComfyUI custom nodes within days of arXiv release. The registry-clone-pip model lowered the barrier to node publication to the point where a single PhD student’s experimental implementation of a new sampling algorithm could be used by thousands of artists the same week. This velocity of community innovation is the primary value ComfyUI Manager delivers, and it explains both why the extension is treated as effectively mandatory and why Comfy-Org formally absorbed it into the Comfy-Org GitHub Organisation namespace in March 2025.

The extension’s architectural position within the ComfyUI server is significant. It implements as a Python backend module that hooks into ComfyUI’s extension loading path — running within the same process and Python environment as the inference engine — and a JavaScript frontend component that adds a management panel to ComfyUI’s Lit-element-based web interface. The registry JSON is fetched from a GitHub-hosted canonical source (now also mirrored at registry.comfy.org), enabling community contribution of new package listings via pull request without requiring Manager itself to be updated. Node installation delegates installation entirely to Git clone plus pip requirements install, meaning every installed custom node retains its full repository history and can be version-pinned, rolled back, or inspected via standard Git operations. This architecture kept dependency on ComfyUI Manager itself minimal while leveraging universal developer tooling, which explains both its rapid adoption and its architectural limitations: pip’s dependency resolution is not deterministic without lock files, and Git-based installation means package integrity depends on the upstream repository remaining available and unmodified at the installed commit.

The Snapshot Management capability addresses the reproducibility gap directly. A snapshot serialises the exact set of installed custom nodes, their commit hashes, and (since version 3.38) Python package dependencies to a timestamped JSON file stored in the user’s protected Manager data directory. When a user performs an “Update All” operation, Manager automatically saves a pre-update snapshot as a safety net, enabling rollback if a node update introduces incompatibilities. Studios can treat snapshot files as version-controlled environment specifications analogous to requirements.txt or Pipfile.lock, enabling deterministic environment recreation across developer machines or CI/CD build agents — though without the complete transitive dependency locking that Docker or Conda environments provide.

Components / Architecture

Custom Node Registry — the primary registry is a JSON file (custom-node-list.json) hosted in the Comfy-Org/ComfyUI-Manager GitHub repository, listing community node packages with name, description, author, installation URL, tags, and dependency declarations. Since 2025, the Comfy Node Registry at registry.comfy.org provides an additional, moderated channel with pre-built packages and improved conflict resolution. Manager pulls the registry on startup and on manual refresh, populating the browsable node list.

One-Click Installer — accepts a node registry entry and executes: git clone <url> custom_nodes/<name>, then pip install -r requirements.txt (or pip install -e . for editable installs, or uv pip install where uv is available). Installation errors, including pip conflict messages, are surfaced in the frontend panel rather than requiring terminal access.

Missing Node Detector — the core Missing Node Detection algorithm: on workflow JSON import, the detector extracts all class_type values from the workflow node dictionary, compares them against the runtime node class registry (collected from all installed custom node Python modules via ComfyUI’s internal NODE_CLASS_MAPPINGS dict), and presents an install dialogue listing unresolved node types with links to the registry entries that provide them. This detection runs without executing the workflow, making it safe and fast.

Update Manager — polls installed node repositories (via git fetch + git log ORIG_HEAD..HEAD --oneline) to detect new commits since the installed version and surfaces a per-node update status in the UI. Batch update via “Update All” triggers the pre-update snapshot save before applying all updates.

Model Downloader — integrates with Hugging Face Hub (via the Hub Python client API) and CivitAI (via CivitAI’s REST API with optional API key authentication) to browse model files — checkpoints, LoRA adapters, VAE decoders, ControlNet weights — and download them directly into the correct ComfyUI model subdirectory (models/checkpoints/, models/loras/, etc.) without manual file placement.

Snapshot Export / Import — serialises the installed environment to <USER_DIRECTORY>/default/ComfyUI-Manager/snapshots/<timestamp>.json. A snapshot records: ComfyUI version, Manager version, each installed custom node’s repository URL and commit hash, and (v3.38+) a pip requirements hash. Import applies the snapshot by checking out the pinned commits and running dependency installs, supporting cross-machine environment parity.

Disable / Enable Toggle — marks individual custom nodes as disabled by renaming their directory with a disabled- prefix, preventing ComfyUI’s extension loader from importing the module without deleting the installation. This enables rapid A/B debugging of node conflicts without environment destruction.

Security Patch (CVE-2025-67303) — version 3.38 (2025) migrated Manager’s data directory from ComfyUI/user/default/ComfyUI-Manager/ (which was accessible via ComfyUI’s unauthenticated web file API in ComfyUI versions prior to 0.3.76) to a protected path outside the web root, closing the information disclosure vector catalogued as CVE-2025-67303.

Custom Node Ecosystem — Representative Packages

Understanding the breadth of the custom node ecosystem that ComfyUI Manager enables requires examining representative packages across the major capability domains. The following survey covers packages with the highest install counts and most significant capability contributions, all discoverable and installable through Manager’s Custom Node Registry:

Sampling and Conditioning Control — ComfyUI-Impact-Pack (ltdrdata, the ComfyUI Manager author) provides advanced segmentation via YOLO-based detectors, enabling face detection, bounding-box-based inpainting, and iterative refinement workflows. comfyui_controlnet_aux provides pre-processing nodes for all major ControlNet map types: OpenPose skeleton extraction, Midas/DPT depth estimation, HED edge detection, MLSD line detection, uniformer semantic segmentation, and tile-based conditioning. This single package manages dozens of preprocessor model files, all downloadable via Manager’s Model Downloader. ComfyUI-Advanced-ControlNet extends the base ControlNet nodes with timestep-range conditioning, weight scheduling, and multi-ControlNet combination.

Style and Reference Transfer — ComfyUI-IPAdapter-Plus implements IP-Adapter reference image injection with advanced features: multiple reference images per conditioning, face-focused IP-Adapter variants, regional IP-Adapter for spatially localised style injection, and IP-Adapter plus ControlNet combination for structure-plus-style conditioning. The WAS Node Suite provides over 210 utility nodes covering image manipulation, text processing, conditional logic, file I/O, and external API integration — a comprehensive utility layer for complex multi-step workflow construction. As Dr.Lt.Data also authored this suite, it is the canonical demonstration of his node development philosophy.

Video and Animation — ComfyUI-AnimateDiff-Evolved is the primary AnimateDiff integration, providing temporal motion module injection into Stable Diffusion UNets, camera motion control via AnimateDiff’s CameraControl extension, and support for AnimateDiff-Lightning distilled models for faster generation. ComfyUI_FizzNodes adds prompt scheduling nodes for keyframe-based animation where prompt weights vary continuously over time. ComfyUI-VideoHelperSuite provides video loading, frame extraction, and video compilation nodes closing the video input-output pipeline. ComfyUI-WanVideoWrapper integrates Wan2.1 — the leading open-source text-to-video model as of 2025 — as ComfyUI nodes accessible through the standard API.

Image Enhancement and Post-processing — ComfyUI_ESRGAN wraps ESRGAN, Real-ESRGAN, and SwinIR super-resolution models as upscaling nodes; ComfyUI_FaceRestoration wraps GFPGAN and CodeFormer for Face Restoration within generation pipelines; ComfyUI-SAM integrates Segment Anything Model for mask generation within Inpainting and compositing workflows.

LLM and Agentic Integration — ComfyUI-Autogen exposes AutoGen assistant agents and group chats as ComfyUI nodes, enabling multi-agent dialogue loops within image generation workflows. ComfyUI-LLM-Party integrates multiple LLM providers (OpenAI, Claude, Ollama, Qwen) as node types for dynamic prompt generation, image captioning, and conditional workflow branching. These packages — available through Manager’s registry — transform ComfyUI from a pure image generation tool into a hybrid agentic and generative platform accessible through the same ComfyUI API Specification that drives image-only workflows.

3D and Multimodal — ComfyUI-3D-Pack integrates TripoSR, Zero123, and Stable Zero123 for 3D reconstruction from single images. ComfyUI-UniRig (2025) implements SIGGRAPH 2025 AI rigging for 3D character animation. ComfyUI-AudioScheduler adds audio waveform analysis for music-reactive Image Generation. All of these are installed and managed through ComfyUI Manager, demonstrating the scope of the Community Extension Ecosystem it sustains.

Use Cases / Major Families

Workflow Sharing Communities — Platforms including OpenArt Workflow Registry, Civitai Workflow Sharing, and community Discord servers distribute ComfyUI Workflows as JSON files. Without ComfyUI Manager, recipients unable to run shared workflows due to missing custom nodes faced a manual resolution process that could take hours; with Manager’s Missing Node Detection, the same resolution takes minutes via the install dialogue. This is the use case that drove initial mass adoption.

ControlNet-Augmented Pipelines — Users integrating dozens of ControlNet preprocessor nodes (OpenPose, depth estimation, Canny edge, lineart, normalmap, tile) for structural conditioning of Image Generation rely on Manager to discover, install, and keep current the associated preprocessor node packages (e.g., ComfyUI_ControlNet_Aux) and their model weight files downloaded via the Model Downloader.

Video Generation and Animation — Video Generation workflows using AnimateDiff, Stable Video Diffusion, CogVideoX, ComfyUI-AnimateDiff-Evolved, and Flux.1-based video models require specialised temporal attention node packages not included in the ComfyUI base installation; Manager provides registry discovery and one-click install for these.

IP-Adapter and Style Injection — IP-Adapter integration nodes (ComfyUI-IPAdapter-Plus) that inject reference image style and content encodings into Diffusion Model pipelines are installed and managed via Manager, including downloading the required IP-Adapter weight files from Hugging Face Hub.

Research Prototyping — ML researchers rapidly iterating on novel sampler configurations, attention manipulation techniques, or model fine-tuning approaches install experimental custom node implementations, switch between them using the disable/enable toggle, and capture working environment states via snapshot export before attempting updates — a pattern analogous to git stash in version control.

Professional VFX Production — Studios including UK-based Framestore and Double Negative integrating ComfyUI into production pipelines use Snapshot Management to lock environment states for reproducible frame-batch renders, treating Manager snapshots analogously to Docker layer pinning. The comfy-cli command-line interface to the same snapshot functionality enables CI/CD integration.

Education and Onboarding — Course instructors distributing ComfyUI Workflows as learning materials rely on Manager’s Missing Node Detection to eliminate the traditionally steep manual node installation overhead for course participants, reducing setup friction from hours to minutes.

Registry Architecture — Technical Detail

The registry architecture underlying ComfyUI Manager is deceptively simple but operationally critical. Two primary registries exist as of 2026:

The GitHub Custom Node List — the legacy primary registry, maintained in Comfy-Org/ComfyUI-Manager as custom-node-list.json, a JSON array where each entry has fields: author (GitHub username), title (display name), reference (GitHub repository URL), files (list of Python files registering node classes, used for class_type mapping), install_type (one of git-clone, copy, unzip, pip), description (plain text), and tags (array of capability strings such as "image", "video", "controlnet", "sampling"). A companion file extension-node-map.json maps from repository URLs to the class_type strings they provide, enabling Missing Node Detection without cloning the repository. This mapping is updated by the Manager registry pull process and stored locally, decoupling the detection query from network availability.

The Comfy Node Registry (CNR) — the official registry at registry.comfy.org, a PyPI-compatible package index where custom node authors publish packages via comfy-cli publish. CNR packages include a manifest with metadata, pre-built Python wheels for common platforms (eliminating compilation), a nodes.json file listing registered class_type strings, and optional models.json listing model dependencies with download URLs and SHA-256 hashes. CNR packages receive a moderation review for basic code quality and absence of obvious malicious code before acceptance — a weaker but present bar compared to the zero-moderation GitHub list. Integration with uv’s wheel cache makes CNR installs dramatically faster than git-clone-plus-pip-from-source for packages with binary dependencies.

The extension-node-map.json file is the data structure enabling Missing Node Detection without network access. During startup, Manager builds an in-memory mapping from class_type strings to the providing repository by merging: (a) the locally stored extension-node-map.json from the last registry pull, and (b) live scanning of installed custom_nodes/ Python modules via ComfyUI’s NODE_CLASS_MAPPINGS dict. When a workflow JSON is imported, the missing-node detector queries this merged mapping for every class_type value in the workflow, identifying nodes that are uninstalled (appear in extension-node-map.json but not in NODE_CLASS_MAPPINGS) and nodes completely unknown to the registry (appear in neither). The latter case — a class_type referencing a private or unreleased node — produces a warning rather than an install prompt, informing the user that the node is not in any known registry.

Snapshot format internals — a Manager snapshot JSON contains at minimum: comfyui_version (semver string), comfyui_manager_version (semver string), nodes (array of objects each with url GitHub repository URL, hash git commit SHA, enabled boolean, and optionally cnr_id for CNR-sourced packages), and metadata (timestamp, platform, Python version). Since version 3.38, the snapshot also includes a pip_freeze_hash — an SHA-256 of the complete pip freeze output at snapshot time — enabling integrity verification during restore even though full transitive version pinning requires importing the full freeze list separately. The comfy-cli tool’s --snapshot argument accepts snapshot files and applies them programmatically, enabling automated environment restoration without the Manager browser UI.

Relationship to the Broader Package Management Ecosystem

ComfyUI Manager’s design choices become clearer when situated within the broader history of package management for specialised developer ecosystems. The progression from manual dependency installation to community registry to governed certified registry closely parallels the evolution of npm (Node.js), pip (Python), and RubyGems: each began as a community-maintained index of manually published packages, evolved governance tooling as security incidents accumulated, and eventually developed enterprise tiers for compliance-constrained users. ComfyUI Manager is roughly at the stage npm occupied in 2016 — a thriving community registry with a growing security vulnerability catalogue and nascent enterprise governance features, but still primarily serving individual developers rather than corporate software supply chains.

The dependency resolution problem ComfyUI Manager delegates to pip (or uv) is fundamentally harder for ML packages than for most software ecosystems, because ML packages have unusually complex CUDA/GPU dependency trees. A single custom node might require: a specific version of PyTorch (itself with CUDA version dependencies), a specific version of xformers (aligned with the PyTorch CUDA version), triton (for kernel compilation), safetensors, transformers, and potentially bitsandbytes (with its own CUDA binary compilation step). These dependency chains interact with the base ComfyUI PyTorch installation in ways that pip’s SAT solver often cannot resolve without manual intervention. The uv solver handles these cases better through pre-built binary wheels, but the fundamental challenge — multiple ML packages requiring conflicting CUDA library versions — remains an active area of Python packaging research. Manager’s Snapshot Management feature is a pragmatic workaround: rather than solving the dependency resolution problem completely, it captures a known-good state and enables restoration to that state, sidestepping resolution for the common case of reproducing an existing environment.

Academic Context

ComfyUI Manager does not emerge from formal package management research but occupies an interesting position at the intersection of software dependency management theory and Generative AI tooling. The dependency resolution problem it addresses — identifying and installing transitive Python dependencies for heterogeneous ML node packages — is the same class of SAT-based problem studied in the package management literature (Abate et al., 2012; Dahlhaus et al., 2020). Manager’s use of pip for dependency resolution inherits pip’s known non-determinism and conflict-resolution limitations, a gap partially addressed by the 2025 adoption of the uv Package Manager backend which implements a Rust-based PubGrub solver with deterministic resolution. The Snapshot Management feature implements concepts from reproducible research infrastructure (Sandve et al., 2013 on “ten simple rules for reproducible computational research”) applied to the ML pipeline context. The proliferation of ComfyUI custom nodes — over 1,000 registered packages in the Comfy Node Registry by 2026 — exemplifies the community extension ecosystem dynamics studied in the open-source software literature (Mens & Demeyer, 2008; Decan et al., 2019 on npm ecosystem vulnerability propagation), with analogous dependency fragility concerns surfacing in CVE reports for ComfyUI extensions. The GenAgent paper (Guo et al., 2024, arXiv:2409.01392) implicitly depends on ComfyUI Manager having established a stable, queryable node registry, since the GenAgent system uses /object_info — populated only by correctly installed custom nodes — to discover available node capabilities for automated workflow construction.

The open-source community extension ecosystem that ComfyUI Manager enables is itself an object of study in the software evolution literature. Decan, Mens, and Grosjean’s (2019) comparative analysis of seven packaging ecosystems found that npm’s rapid growth led to a fragile dependency network with cascading vulnerability propagation — a dynamic now visible in the ComfyUI custom node ecosystem, where a widely-used base node package (such as ComfyUI-Manager itself or the WAS Node Suite) has become a transitive dependency for dozens of other packages. The CVE-2025-67303 incident demonstrated this fragility: a vulnerability in ComfyUI Manager itself affected every ComfyUI installation with Manager installed, which by 2025 represented the vast majority of non-trivial ComfyUI deployments. The Comfy Node Registry’s moderation layer is a direct response to this ecosystem fragility, implementing the kind of security review that PyPI’s Malware Detection team runs for the broader Python ecosystem.

Current Landscape (2026)

In March 2025, the ltdrdata/ComfyUI-Manager repository transferred to the Comfy-Org GitHub Organisation as Comfy-Org/ComfyUI-Manager, formally recognising Dr.Lt.Data’s work as essential ecosystem infrastructure and providing support from the broader Comfy-Org team (blog.comfy.org, 2025). Dr.Lt.Data (the GitHub username of the Korean developer who created the extension) continues as lead maintainer post-migration, with Comfy-Org contributing code review, security response coordination, and registry infrastructure. The migration was framed explicitly as “a natural evolution” rather than an acquisition, preserving the community-first character of the project while anchoring it in the funded company structure.

Concurrent with the migration, ComfyUI Manager was integrated as a bundled default component in the official ComfyUI desktop application (released by Comfy-Org in 2025), which packages ComfyUI with a one-click installer for Windows, macOS (Apple Silicon and Intel), and Linux. This bundling effectively ended the separate installation step for new users in the desktop context, making Manager capabilities available to all ComfyUI desktop users by default — a transition from optional extension to core platform component analogous to how VSCode’s extension marketplace became a defining feature of the editor rather than an add-on.

The Comfy Node Registry (registry.comfy.org), launched 2025 in stages, introduced a governed alternative to the ad hoc GitHub registry. Publishers submit packages via comfy-cli publish (requiring a comfy.org account and package manifest), packages receive moderation review for basic code quality and absence of obvious malicious code, and pre-built wheels eliminate the pip install compilation step for common platforms — addressing the most significant friction point for Windows users with complex CUDA dependency trees. As of June 2026, the CNR lists approximately 400 packages (versus the 1000+ in the legacy GitHub custom-node-list.json registry), with the CNR expected to achieve parity by year-end as node developers migrate to the new publication workflow. The CNR’s moderation requirement creates a quality floor that the GitHub registry lacks, though it also introduces a publication latency — experimental nodes are still published first on GitHub, with CNR registration following after stabilisation.

Support for uv as the dependency resolution backend (configurable in Manager settings) reduced install times for large node packages by one to two orders of magnitude compared to pip on cold caches. The uv pip invocation resolves and downloads binary wheels in parallel, whereas pip’s sequential resolution and build-from-source fallback could take 5-15 minutes for packages with heavy dependencies like xformers or packages requiring CUDA compilation. The comfy-cli command-line tool (pip-installable, separate from the Manager browser extension) provides a programmatic interface to Manager’s snapshot and installation functionality, enabling shell scripting and CI/CD integration patterns.

The security landscape matured through incident response. CVE-2025-67303 (information disclosure via unprotected data path in Manager prior to v3.38, disclosed January 2026) was patched within days of disclosure, with Comfy-Org issuing a coordinated security advisory — the first formal security advisory for the ComfyUI project. The broader ComfyUI cryptomining botnet campaign (documented by Censys in May 2025) specifically targeted unpatched ComfyUI-Manager installations as a reconnaissance vector, accelerating adoption of the v3.38 security update across the user base. Comfy-Org’s 500M post-money valuation (TechCrunch 2026 ComfyUI $500M Valuation) explicitly included investment in security infrastructure for the Comfy Node Registry and Comfy Cloud managed service, with CVE remediation SLAs and package signing roadmap items cited in the funding announcement.

UK Context

The UK Generative AI and VFX communities are among the most intensive adopters of ComfyUI and the Manager extension ecosystem. London-based VFX studios Framestore (reporting 300+ AI R&D staff in 2025), Double Negative (DNEG, with primary offices in London and Manchester), and Milk VFX (London and Cardiff) have publicly reported AI-assisted production workflows using node-based Diffusion Model pipelines where ComfyUI Manager is the operational tooling for node environment management. DNEG’s AI R&D pipeline — used on productions including Oppenheimer, Wonka, and Mission: Impossible — incorporates ComfyUI for concept art generation and texture synthesis workflows; ComfyUI Manager’s Snapshot Management capability enables the DNEG pipeline team to maintain pinned node environments across their distributed rendering infrastructure.

The fxphd training platform (London-headquartered, with global subscriber base) offers professional courses specifically on ComfyUI integration for VFX, covering ComfyUI Manager as the essential installation and maintenance tooling. The ActionVFX platform (with UK-based users prominent in its community) publishes ComfyUI workflow tutorials where Manager is the setup prerequisite. Northern English creative industries hubs are significant: MediaCityUK in Salford (home to BBC, ITV, and Channel 4’s digital operations, dock10 studios, and Dock10’s AI Lab) has Community of Practice groups for Generative AI image tools where ComfyUI Manager is the de facto standard installation reference; Sheffield’s Nesta Digital Innovation and the Screen Yorkshire cluster have funded SME creative companies in AI workflow adoption where ComfyUI Manager is the entry point. Leeds Digital Festival (annual) and Manchester’s GMTech cluster both feature ComfyUI Manager in their generative AI tooling workshops.

UK educational institutions have adopted ComfyUI Manager in creative computing curricula. The Royal College of Art’s School of Design, Goldsmiths’ Department of Computing, and the University of the Arts London’s Creative Computing Institute all include ComfyUI-based image generation in postgraduate programmes, with Manager as the installation layer that makes curriculum delivery tractable at scale. Scotland’s Screen sector has adopted ComfyUI workflows via Edinburgh-based production companies, where the University of Edinburgh’s Informatics faculty (home to the MLP group, with expertise in diffusion models and probabilistic generative modelling) provides the research pipeline that feeds into commercial adoption.

The Open Source Software licensing landscape is a specific UK concern. Legal practitioners at the University of Edinburgh’s SCRIPT Centre for IP law have examined the licensing implications of ComfyUI Manager’s bundled installation of community nodes carrying heterogeneous licences (MIT, Apache 2.0, GPL-2.0, GPL-3.0, AGPL-3.0), noting that GPL-licensed nodes installed into a commercial production ComfyUI deployment may create copyleft obligations for the deployment’s surrounding codebase depending on the GPL version and the nature of the integration. UK-based studios increasingly request licensing audits of their ComfyUI Manager-installed node sets before deploying AI-generated content commercially, a gap the Comfy Node Registry’s moderation process is beginning to address by requiring explicit SPDX licence identifiers in package manifests.

UK-based Hugging Face users represent one of the highest per-capita user concentrations of the Hub API that ComfyUI Manager’s Model Downloader depends on for checkpoint and LoRA weight downloads, reflecting the broader UK ML engineering community’s depth. The UK’s AI Safety Institute (Bletchley Park, established 2023) has engaged with generative AI model provenance concerns that are directly relevant to ComfyUI Manager’s model download trust model — specifically, the absence of cryptographic signing for community-contributed checkpoint files downloaded via Manager’s Model Downloader presents an integrity risk that the SHA-256 hash verification being added in Comfy Node Registry model manifests directly addresses.

Future Directions (2026–2030)

Several development trajectories are well-evidenced from the 2026 position. First, the Comfy Node Registry (registry.comfy.org) will increasingly displace the ad hoc GitHub registry as the primary node distribution channel, with certification tiers (community, verified, enterprise-certified) enabling studios to maintain approved node whitelists and receive security advisories for installed packages. This mirrors the trajectory of the npm registry’s @types and @npmcorp verified namespace model, where governance layers accreted atop an initially ungoverned registry. Comfy-Org’s confirmed enterprise customers — Netflix, Apple, Ubisoft — have the purchasing power to drive a certified node programme analogous to the Apple App Store review process for ComfyUI production environments.

Second, Snapshot Management will evolve toward full environment lockfiles that pin transitive Python package versions deterministically (analogous to poetry.lock or uv’s uv.lock), closing the reproducibility gap between Manager snapshots and container-based environment management. The current snapshot format records custom node commit hashes but not the transitive pip dependency graph; a future comfyui-manager.lock format will address this, likely integrating with uv’s lockfile format to leverage its deterministic PubGrub solver output.

Third, the comfy-cli command-line interface — the CLI counterpart to the Manager browser panel, installable via pip install comfy-cli — will gain CI/CD-optimised subcommands enabling snapshot-based environment restoration in automated build pipelines without a running ComfyUI server. This separates environment management (a build-time concern) from inference execution (a runtime concern), enabling Studios to run Manager-equivalent operations in Docker build steps without starting the full ComfyUI server.

Fourth, the uv Package Manager integration will become the default dependency resolution backend, supplanting pip for new installations. The uv PubGrub solver’s deterministic output and order-of-magnitude faster resolution times (sub-second for most node packages versus 10-60 seconds for pip) will substantially improve the one-click install experience, particularly on Windows where CUDA-dependent packages have historically required manual conflict resolution.

Fifth, enterprise governance features — per-organisation node registries, audit logs for node installations, CVE-feed integration that automatically flags installed nodes against the Comfy Node Registry’s vulnerability database, and approved-list enforcement that prevents installation of uncertified nodes in production environments — will be developed for the enterprise customer segment. This positions ComfyUI Manager as an enterprise software asset management tool rather than merely a community convenience extension, analogous to the transition JFrog Artifactory made from a local Maven mirror to an enterprise artifact management platform.

Sixth, model discovery and management will deepen substantially. The Model Downloader will gain integration with the Comfy Node Registry’s model index (currently in development), enabling registry-mediated download of quantised (GGUF, INT8, INT4) and distilled model variants alongside community-contributed fine-tunes, with SHA-256 hash verification as a first-class citizen preventing corrupted or tampered model weights from entering production pipelines. Integration with emerging model provenance standards (e.g., the C2PA coalition’s content credentials for AI-generated content) will further distinguish enterprise-certified models from community-contributed models in the download interface, addressing the licensing and attribution requirements that professional studios face when using AI-generated content in commercial productions.

Seventh, the migration of ComfyUI Manager’s data store away from the legacy ComfyUI/user/default/ path (driven by CVE-2025-67303) will be extended to a formally specified, versioned storage schema that supports multi-user ComfyUI deployments, where different users maintain separate node environments layered over a shared base installation. This multi-user architecture is essential for the Comfy Cloud managed service as it scales beyond individual developer accounts to team and organisation-level deployments.

Key Terminology

  • Custom Node — a Python module placed in ComfyUI’s custom_nodes/ directory that registers one or more node class_type strings in NODE_CLASS_MAPPINGS, extending the available node palette. Custom nodes can implement any computation, from image preprocessing through LLM API calls to 3D mesh operations.
  • custom-node-list.json — the JSON registry file maintained in the Manager repository listing available community custom node packages with metadata; the primary data source for Manager’s browsable install list, now complemented by the Comfy Node Registry API.
  • Snapshot — a Manager-generated JSON file recording the complete installed environment state (custom node repositories, commit hashes, ComfyUI version, Manager version) enabling deterministic environment recreation.
  • Missing Node Detection — the process of comparing class_type values in an imported workflow JSON against the runtime NODE_CLASS_MAPPINGS dict to identify nodes that are unavailable in the current installation and require installation via Manager.
  • Comfy Node Registry (CNR) — the governed, PyPI-compatible node distribution platform at registry.comfy.org, launched 2025 by Comfy-Org GitHub Organisation, providing moderated package submissions, pre-built wheels, and version-pinned dependencies as a more reproducible alternative to direct Git repository installation.
  • Disable / Enable Toggle — Manager’s mechanism for deactivating a custom node by renaming its directory with a disabled- prefix, preventing import by ComfyUI’s extension loader without deleting the installation, used for conflict debugging and A/B testing.
  • uv — a Rust-based Python package manager by Astral, integrated in ComfyUI Manager since 2025, offering deterministic dependency resolution via PubGrub algorithm and significantly faster installs than pip through pre-built wheel caching.
  • git-clone install type — the default installation method for GitHub-registry custom nodes: Manager executes git clone <repository_url> custom_nodes/<node_name>, then runs pip install -r requirements.txt (or pip install -e . for editable installs). The installed node retains the full Git repository history, enabling rollback to any prior commit via git checkout <sha> and version inspection via git log.
  • pip install type — an alternative registry entry install_type where the node is distributed as a pip package on PyPI rather than as a raw Git repository; Manager executes pip install <package_name> directly. Used for professionally packaged nodes and for Comfy Node Registry entries that publish pre-built wheels.
  • NODE_CLASS_MAPPINGS — the Python dictionary that ComfyUI’s extension loading system collects from each custom node’s __init__.py by calling NODE_CLASS_MAPPINGS.update(...) (or by reading the returned value of the module’s __init__.py). Maps class_type strings (the node identifiers in workflow JSON) to Python class objects implementing the node. This dict is the runtime source of truth that Missing Node Detection compares against.
  • extension-node-map.json — the registry-side index maintained by Manager mapping GitHub repository URLs to the class_type strings they register. Populated by the Manager maintainer from periodic scans of the registry. Enables Missing Node Detection without cloning or importing the repositories being queried.
  • update-all — a Manager UI action that fetches the latest commits for all installed Git-type custom nodes, saves a pre-update snapshot, and runs git pull plus pip install for each installed node. The most common cause of ComfyUI environment breakage, as individual node authors do not coordinate release cycles; the pre-update snapshot enables rollback.
  • alt-install — Manager’s model hash verification feature that detects when a model file exists in the ComfyUI model directories under a different filename from the registry entry’s expected filename, preventing redundant multi-gigabyte downloads of already-present model weights.

Interoperability and Downstream Tools

ComfyUI Manager’s data model and registry format have become reference specifications for a broader set of tooling built around ComfyUI environment management:

comfy-cli — the official command-line interface to ComfyUI Manager functionality, installable via pip install comfy-cli. Provides subcommands: comfy install (install ComfyUI and Manager from scratch), comfy node install <name> (install a specific custom node by registry name), comfy node update --all (update all installed nodes), comfy snapshot export (export current environment as JSON snapshot), comfy snapshot restore <file> (restore from snapshot), comfy model download (download models by name from registry). The CLI enables shell scripting and CI/CD integration patterns that require Manager functionality without a browser UI, and is the recommended approach for Dockerised ComfyUI environments where Manager’s browser panel is inaccessible.

comfyui-manager PyPI package — as of 2025, ComfyUI Manager is also published as a pip-installable package (pip install comfyui-manager), enabling installation via the standard Python toolchain rather than requiring Git clone. This supports automated environment setup in Docker build contexts and enables comfy-cli-mediated installs that do not require a pre-existing ComfyUI installation.

Workflow snapshot as CI artefact — studios and research teams using ComfyUI in automated pipelines treat Manager snapshot files as version-controlled CI artefacts, committing them alongside workflow JSON files. On each CI run, the pipeline uses comfy snapshot restore to establish a known-good node environment before re-executing the workflow. Combined with model weight SHA-256 verification, this creates a fully deterministic generation pipeline suitable for visual regression testing.

Docker base image integration — Comfy-Org and the community maintain Docker base images (e.g., ghcr.io/comfy-org/comfyui-base) that include ComfyUI, Manager, and a configurable set of pre-installed custom nodes specified via environment variables or a snapshot file mounted at build time. This containerised approach combines Manager’s ecosystem reach with Docker’s reproducibility guarantees, addressing the strongest criticism of the Manager-only approach (pip non-determinism) by layering Manager node management over a container-pinned Python base.

Security and Trust Considerations

The ComfyUI Manager extension and the custom node ecosystem it manages present several distinct security and trust challenges that differ materially from typical software package management:

Code execution on install — custom node installation via Git clone and pip install is a fully privileged code execution event. A malicious requirements.txt or a malicious __init__.py in a custom node repository can execute arbitrary code on the ComfyUI user’s machine during installation. Unlike pip packages on PyPI, which receive at least minimal automated malware scanning, GitHub-registry nodes receive no automated scanning before appearing in Manager’s install list. The Comfy Node Registry’s moderation review addresses this for CNR-listed packages but not for GitHub-only packages. Users installing arbitrary nodes from the GitHub registry are implicitly trusting the node author’s GitHub account security and code review practices.

Dependency confusion attacks — custom nodes that install Python dependencies with names similar to popular packages (the “dependency confusion” attack vector documented by Alex Birsan in 2021) could introduce malicious packages into a ComfyUI environment if pip’s resolution prefers a malicious PyPI package over the intended private package. uv’s explicit --index-url configuration and package pinning reduce but do not eliminate this risk. Production environments should maintain pip/uv configuration with --extra-index-url ordering that prioritises verified sources.

CVE-2025-67303 post-mortem — the information disclosure vulnerability affected Manager data files stored in ComfyUI/user/default/ComfyUI-Manager/, which was accessible via ComfyUI’s unauthenticated web API in ComfyUI versions prior to v0.3.76. The exposed data included Manager’s configuration, cached registry entries, and potentially API keys stored in Manager’s model download credentials. The fix (Manager v3.38) migrated Manager’s data to a path outside the web root; ComfyUI v0.3.76 restricted the paths accessible via the /user endpoint. The incident highlighted that Manager’s privileged access to the ComfyUI installation — it reads and writes to custom_nodes/, models/, and configuration files — makes it a high-value attack target that must be kept updated promptly.

Model integrity — model files downloaded via Manager’s Model Downloader from Hugging Face Hub and CivitAI are verified by file size (if the registry entry specifies an expected size) but not by cryptographic hash in the current implementation. A compromised CDN or a man-in-the-middle attack could substitute a malicious model file that executes arbitrary code during PyTorch tensor loading (the torch.load vulnerability with pickle format, mitigated by the safetensors format but not eliminated for legacy .ckpt files). The Comfy Node Registry model manifest format’s SHA-256 hash verification — when fully implemented and enforced — will close this gap for CNR-listed models.

Comparison with Alternative Extension Management Approaches

ComfyUI Manager’s design choices become clearer when compared to alternative approaches to ComfyUI environment management:

Manual Git clone workflow — the pre-Manager method: manually git clone each custom node repository into custom_nodes/, manually run pip install -r requirements.txt, manually identify missing nodes from workflow JSON by reading the class_type fields and searching GitHub. This approach is transparent and gives maximum control but is prohibitively labour-intensive for environments with more than a handful of custom nodes. Manager automates all of this while preserving the underlying Git-based model.

AUTOMATIC1111 Stable Diffusion WebUI Extensions — the analogous system for the AUTOMATIC1111 ecosystem. Similar design: a browser-accessible extension tab, a community-maintained index (the AUTOMATIC1111/stable-diffusion-webui-extensions repository on GitHub), Git clone installation, pip dependency management. The primary differences are that A1111 extensions are harder to transfer between environments (no snapshot export equivalent) and the registry is entirely community-contributed with no Comfy Node Registry-equivalent moderation tier. ComfyUI Manager’s Snapshot Management capability is a significant advance over the A1111 extension model.

Conda environment management — the ML community standard for Python environment isolation: conda create -n comfyui python=3.10, conda install pytorch torchvision torchaudio, then git-clone custom nodes. Conda environments provide stronger dependency isolation than Manager’s pip-into-the-base-environment model, with full transitive package locking via conda env export. The trade-off is that Conda environments require more expertise, cannot be managed from a browser UI, and do not have the custom node discovery / missing-node detection capabilities that Manager provides. Production deployments often layer both: Conda or venv for Python package isolation, ComfyUI Manager for custom node lifecycle management within that isolated environment.

Docker containerisation — the strongest reproducibility guarantee: a Docker image captures the complete operating system state including CUDA drivers, Python packages, and installed custom nodes. Comfy-Org and the community publish base Docker images that can be extended with node installations via comfy-cli in the Dockerfile. The limitation is that Docker build cycles (minutes to tens of minutes for CUDA-dependent packages) are too slow for the experimental iteration pattern that ComfyUI Manager’s one-click install enables. The practical outcome is that most productions use both: Manager for development iteration, Docker for production deployment using snapshots generated during development.

Nix flakes / NixOS — an emerging approach in the research community: Nix’s functional package management provides fully reproducible, bit-for-bit-identical environments across machines without containerisation overhead. Several community members have published ComfyUI Nix flakes that specify the exact custom node set, versions, and Python dependencies declaratively. Nix addresses all of Manager’s reproducibility limitations but requires significant expertise and is not compatible with Manager’s browser-based UX. This approach is unlikely to displace Manager in the mainstream but represents the theoretical ideal that Manager’s Snapshot Management evolution aims toward.

Research & Literature

  1. ltdrdata [Dr.Lt.Data] (2023). ComfyUI-Manager: An extension for managing ComfyUI custom nodes. GitHub. https://github.com/Comfy-Org/ComfyUI-Manager
  2. Comfy-Org Blog (2025). Meet the new ComfyUI-Manager. https://blog.comfy.org/p/meet-the-new-comfyui-manager
  3. comfyanonymous (2023). ComfyUI: The most powerful and modular diffusion model GUI and backend. GitHub. https://github.com/comfyanonymous/ComfyUI
  4. Comfy-Org (2025). ComfyUI-Manager: Support Comfy Node Registry (CNR). GitHub PR #1356. https://github.com/Comfy-Org/ComfyUI-Manager/pull/1356
  5. Rombach, R., Blattmann, A., Lorenz, D., Esser, P., & Ommer, B. (2022). High-resolution image synthesis with latent diffusion models. CVPR 2022.
  6. Zhang, L., Rao, A., & Agrawala, M. (2023). Adding conditional control to text-to-image diffusion models. ICCV 2023. arXiv:2302.05543.
  7. Ye, H., Zhang, J., Liu, S., Han, X., & Wei, Y. (2023). IP-Adapter: Text compatible image prompt adapter for text-to-image diffusion models. arXiv:2308.06721.
  8. Hu, E.J., Shen, Y., Wallis, P., et al. (2022). LoRA: Low-rank adaptation of large language models. ICLR 2022.
  9. Guo, X., Wu, Q., Liu, J., et al. (2023). AnimateDiff: Animate your personalized text-to-image diffusion models without specific tuning. arXiv:2307.04725.
  10. Guo, X. et al. (2024). GenAgent: Build collaborative AI systems with automated workflow generation — case studies on ComfyUI. arXiv:2409.01392.
  11. Podell, D., English, Z., Lacey, K., et al. (2023). SDXL: Improving latent diffusion models for high-resolution image synthesis. arXiv:2307.01952.
  12. Black Forest Labs (2024). Flux.1: High-performance text-to-image generation. https://blackforestlabs.ai
  13. Abate, P., Di Cosmo, R., Guesdon, J.L., & Zacchiroli, S. (2012). Dependency solving: A separate concern in component evolution management. Journal of Systems and Software, 85(10).
  14. Decan, A., Mens, T., & Grosjean, P. (2019). An empirical comparison of dependency network evolution in seven software packaging ecosystems. Empirical Software Engineering, 24(1).
  15. Sandve, G.K., Nekrutenko, A., Taylor, J., & Hovig, E. (2013). Ten simple rules for reproducible computational research. PLOS Computational Biology, 9(10).
  16. NVD (2025). CVE-2025-67303: ComfyUI-Manager information disclosure via unprotected data path. https://nvd.nist.gov/vuln/detail/CVE-2025-67303
  17. Censys (2025). Hackers are attempting to turn ComfyUI servers into a cryptomining proxy botnet. https://censys.com/blog/comfyui-servers-cryptomining-proxy-botnet/
  18. TechCrunch (2026). ComfyUI hits $500M valuation as creators seek more control over AI-generated media. https://techcrunch.com/2026/04/24/comfyui-hits-500m-valuation-as-creators-seek-more-control-over-ai-generated-media/
  19. Comfy-Org Blog (2026). ComfyUI raises $30M to scale open-source AI for creative production. https://blog.comfy.org/p/comfyui-raises-30m-to-scale-open
  20. pypi.org (2025). comfyui-manager. https://pypi.org/project/comfyui-manager/
  21. DeepWiki (2025). Snapshot management — Comfy-Org/ComfyUI-Manager. https://deepwiki.com/Comfy-Org/ComfyUI-Manager/6.1-snapshot-management
  22. ComfyUI Wiki (2025). How to install ComfyUI custom nodes (plugins). https://comfyui-wiki.com/en/install/install-custom-nodes
  23. ActionVFX (2025). ComfyUI for VFX. https://www.actionvfx.com/blog/comfyui-for-vfx
  24. fxphd (2025). Generative AI for VFX with ComfyUI and InvokeAI. https://www.fxphd.com/details/713/
  25. Astral (2024). uv: An extremely fast Python package manager. https://github.com/astral-sh/uv
  26. Huawei Cloud Security (2026). ComfyUI-Manager API unauthorized access vulnerability (CVE-2025-67303). https://www.huaweicloud.com/eu/notice/20260107120018062.html
  27. comfyui.org (2025). ComfyUI-Manager: A new chapter in custom node evolution. https://comfyui.org/en/comfyui-manager-custom-node-evolution
  28. BentoML (2025). ComfyUI: Deploy workflows as APIs. https://docs.bentoml.com/en/latest/examples/comfyui.html

Provenance