From f39cbd56fecae0b27a446c0cd450cd591f3a8bea Mon Sep 17 00:00:00 2001 From: "Dr.Lt.Data" Date: Wed, 19 Aug 2026 08:43:25 +0900 Subject: [PATCH] fix(custom-node-list): demote mickmumpitz/ComfyUI-SplatKit from default to dev channel (security hold) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Post-registration full re-verify (§14.7) found an unauthenticated CSRF-reachable arbitrary-directory delete: DatasetProject.make(reset=True) runs shutil.rmtree on an uncontained os.path.join(output_dir, dataset_name) (nodes/common.py:169-173) — an absolute or ..-containing name escapes the output dir. Removed from default + node_db/new, added to node_db/dev with [SECURITY ISSUE] suffix (reversible install-block, §4.7-H mechanic). Restore to default on author fix (realpath+commonpath containment) + re-verify pass. --- custom-node-list.json | 11 ----------- node_db/dev/custom-node-list.json | 11 +++++++++++ node_db/new/custom-node-list.json | 11 ----------- 3 files changed, 11 insertions(+), 22 deletions(-) diff --git a/custom-node-list.json b/custom-node-list.json index 554e85987..6caab0389 100644 --- a/custom-node-list.json +++ b/custom-node-list.json @@ -60971,17 +60971,6 @@ "install_type": "git-clone", "description": "OpenAI API based prompt rewriting agents for MiniMax H3 T2VA/I2VA/L2VA/FL2VA and Ref2VA workflows, using the official H3 skill files." }, - { - "author": "mickmumpitz", - "title": "ComfyUI-SplatKit", - "id": "splatkit", - "reference": "https://github.com/mickmumpitz/ComfyUI-SplatKit", - "files": [ - "https://github.com/mickmumpitz/ComfyUI-SplatKit" - ], - "install_type": "git-clone", - "description": "Build 3D Gaussian Splat training datasets from a single 360 panorama, inside ComfyUI." - }, { "author": "Andy294753951", "title": "ComfyUI-Flow-Wrangler", diff --git a/node_db/dev/custom-node-list.json b/node_db/dev/custom-node-list.json index 214a53daa..a26ea970f 100644 --- a/node_db/dev/custom-node-list.json +++ b/node_db/dev/custom-node-list.json @@ -1,5 +1,16 @@ { "custom_nodes": [ + { + "author": "mickmumpitz", + "title": "ComfyUI-SplatKit [SECURITY ISSUE]", + "id": "splatkit", + "reference": "https://github.com/mickmumpitz/ComfyUI-SplatKit", + "files": [ + "https://github.com/mickmumpitz/ComfyUI-SplatKit" + ], + "install_type": "git-clone", + "description": "Build 3D Gaussian Splat training datasets from a single 360 panorama, inside ComfyUI." + }, { "author": "yitao2020", "title": "ComfyUI-GPT-Image-2 [NAME CONFLICT]", diff --git a/node_db/new/custom-node-list.json b/node_db/new/custom-node-list.json index d711df94e..a652edd5b 100644 --- a/node_db/new/custom-node-list.json +++ b/node_db/new/custom-node-list.json @@ -222,17 +222,6 @@ "install_type": "git-clone", "description": "A ComfyUI custom node pack for image captioning and text generation with ToriiGate-0.5, a fine-tuned Qwen3.5-4B model." }, - { - "author": "mickmumpitz", - "title": "ComfyUI-SplatKit", - "id": "splatkit", - "reference": "https://github.com/mickmumpitz/ComfyUI-SplatKit", - "files": [ - "https://github.com/mickmumpitz/ComfyUI-SplatKit" - ], - "install_type": "git-clone", - "description": "Build 3D Gaussian Splat training datasets from a single 360 panorama, inside ComfyUI." - }, { "author": "Andy294753951", "title": "ComfyUI-Flow-Wrangler",