5 min read

Krita AI Diffusion: Generative Fill Inside Krita (GitHub, Scanned)

A Krita plugin for AI inpainting, outpainting, live painting and upscaling on your own GPU.

Krita AI Diffusion logo
✅
Scan: safe. Nothing to warn about. The hits are a cloud Docker image built by the author, and the plugin's updater checks a hash before installing a new version. Scanned Sep 27, 2026; the full report is below.

Krita AI Diffusion puts image generation inside Krita, the free painting app, so AI becomes one more tool on the canvas instead of a separate website. Select an area and fill it, extend the canvas, or remove an object; turn on live painting and the AI reinterprets your sketch as you draw; guide results with scribble, line art, depth, pose and other control layers, or with reference images for style and composition; give different layers their own prompts with regions; and upscale to 4K, 8K and beyond without running out of memory.

Behind the scenes it drives ComfyUI, which the plugin can install and manage for you, or it connects to an existing local or remote ComfyUI server. It supports Flux 2, Z-Image, Stable Diffusion 1.5 and XL, Illustrious and text-instructed edit models, with your own checkpoints and LoRAs through presets. The emphasis is control: it is built for people who paint and edit, not for producing whole images from a single prompt.

The plugin is developed by Acly, licensed GPL-3.0, with about 10,700 stars and version 1.53.0, and its live-painting clips circulate widely on TikTok. It runs on Windows, Linux and macOS. Generating locally wants an NVIDIA GPU with at least 6 GB of VRAM, and an optional cloud service at interstice.cloud covers machines without one.

Who it is for

Digital painters, illustrators and concept artists who want AI help inside a real editing workflow, and photo editors who want generative fill without an Adobe subscription.

Getting started

1. Install Krita 5.2.0 or newer (macOS shown; Windows and Linux builds are on krita.org)

brew install --cask krita

2. Download the plugin ZIP from the latest release

curl -LO https://github.com/Acly/krita-ai-diffusion/releases/download/v1.53.0/krita_ai_diffusion-1.53.0.zip

3. In Krita, import the ZIP, restart, and open the docker; then click Configure to install or connect a server

Tools > Scripts > Import Python Plugin from File, then Settings > Dockers > AI Image Generation

The managed local server downloads ComfyUI, its extensions and the models you select, which takes several gigabytes. Without an NVIDIA GPU with 6 GB or more, generation is very slow or fails. Krita's official channels do not support the plugin; ask in its GitHub discussions or Discord instead.

Safety scan

We cloned Acly/krita-ai-diffusion at commit 26aec6c on Sep 27, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.

  • No secrets and no bare-IP URLs across 625 files and about 56,000 lines, mostly Python. Git LFS holds only test images, so the scanned code is complete.
  • Both pattern hits are in scripts/docker/Dockerfile, which installs uv and rclone by piping their official installers to a shell while building the server image for cloud GPU hosts. The installer flagged as editing a shell profile is that image's start.sh, which adds an environment line to the container's own .bashrc and your SSH public key to its authorized_keys.
  • We read the update code. ai_diffusion/model/updates.py asks api.interstice.cloud for the latest plugin version, sending the current version number, and when you choose to update it downloads the ZIP and refuses it if the SHA-256 does not match. The hash comes from the same server, so this guards against corruption rather than a compromised server. The managed local install fetches ComfyUI and models from GitHub and Hugging Face.
  • 107 known advisories (3 critical, 49 high), none in the plugin itself, which has no lockfile. docs/package-lock.json (82) is the Astro documentation site, and scripts/docker/requirements.txt (25, including a PyJWT critical) is the cloud server image.
  • One workflow, not using pull_request_target, with one third-party action pinned to a tag. Licence and contributing guide present; no security policy, Dependabot or CodeQL.

What the scanner counted

CheckResult
SecretsNone found.
Suspicious code2 pattern hits found and read; every one is listed under the raw findings.
Install-time code1 installer script (one edits your shell profile)
Committed binariesNone.
CI workflows1 workflow. None use pull_request_target. 1 of 1 third-party action pinned to a tag rather than a commit.
Network hosts21 distinct hosts referenced from source; most often github.com, docs.interstice.cloud, www.interstice.cloud, api.interstice.cloud. No URLs to bare IP addresses.
Known vulnerabilities107 advisories across 747 pinned packages: 3 critical, 49 high, 44 moderate, 11 low. docs/package-lock.json: 542 packages, 82 advisories; scripts/docker/requirements.txt: 207 packages, 25 advisories.
Project hygieneHas licence file, contributing guide. Missing security policy, automated dependency updates, CodeQL.
OpenSSF ScorecardNot scored: the project is not in Scorecard's weekly index.

The raw findings

Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.

Pattern hits (2)
WhereRuleMatch
scripts/docker/Dockerfile:35download-piped-to-shellRUN curl -LsSf https://astral.sh/uv/install.sh | sh
scripts/docker/Dockerfile:78download-piped-to-shellRUN curl https://rclone.org/install.sh | bash
Installer scripts (1)
Worst known vulnerabilities (24 of 107)
AdvisorySeverityPackageSummary
GHSA-26w7-cxv4-gfx2criticalastro@5.18.1Astro: Remote code execution through AVIF image optimization
GHSA-23hp-3jrh-7fpwcriticaltar@7.5.11node-tar: Decompression/parse DoS via unlimited input
GHSA-ffc3-869f-jxw9criticalpyjwt@2.13.0PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guar…
GHSA-c2c7-rcm5-vvqjhighpicomatch@2.3.1Picomatch has a ReDoS vulnerability via extglob quantifiers
GHSA-2pvr-wf23-7pc7highastro@5.18.1Astro: Host header SSRF in prerendered error page fetch
GHSA-8hv8-536x-4wqphighastro@5.18.1Astro: Reflected XSS via unescaped slot name
GHSA-f88m-g3jw-g9cjhighsharp@0.34.5sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591
GHSA-rgj7-g3m4-5g8chighsharp@0.34.5sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545
GHSA-2p49-hgcm-8545highsvgo@4.0.1SVGO removeScripts plugin leaves some executable scripts intact
GHSA-w27v-7q3p-w38rhighsvgo@4.0.1SVGO: removeScripts allows executable links through namespace and control-character bypasses
GHSA-737v-mqg7-c878highdefu@6.1.4defu: Prototype pollution via `__proto__` key in defaults argument
GHSA-77vg-94rm-hx3phighdevalue@5.6.4Svelte devalue: DoS via sparse array deserialization
GHSA-j22f-vq7h-c4qmhighdevalue@5.6.4devalue: `stringify`/`uneval` serialize shared memory
GHSA-mcm9-63f2-9j32highdevalue@5.6.4devalue: Repeated primitive strings cause quadratic expansion in uneval
GHSA-r9w8-h9r3-54w4highdevalue@5.6.4devalue: Custom ArrayBuffer revivers can bypass typed-array allocation validation
GHSA-7pqw-9j4j-h8q3highextract-zip@2.0.1extract-zip allows arbitrary file writes through symlink archive entries
GHSA-jmr9-qjv8-65gvhighextract-zip@2.0.1extract-zip unvalidated symlink path traversal
GHSA-ch52-4w7c-c8xphighhttp-cache-semantics@4.2.0http-cache-semantics max-stale handling can disclose cross-user cached responses
GHSA-2883-xcg3-v3hhhighjs-yaml@4.1.1js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
GHSA-52cp-r559-cp3mhighjs-yaml@4.1.1js-yaml: YAML merge-key chains can force quadratic CPU consumption
GHSA-5p4m-2wfm-xmqjhighjs-yaml@4.1.1JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) - CVE-2026-59870 fix not backported
GHSA-28wg-ghj8-5hjvhighnanoid@3.3.11nanoid: non-secure generators can loop indefinitely with negative size
GHSA-2v37-7h3g-55p8highnanoid@3.3.11nanoid: custom generators can loop indefinitely when size is zero
GHSA-xwg4-73v4-xw9whighnanoid@3.3.11nanoid: Integer Overflow or Wraparound

By the numbers

Stars10.7K
Forks636
Contributors51
Commits1,782
Open issues104
Open pull requests11
Releases82
Latest releasev1.53.0
LicenceGPL-3.0
Main languagePython
Project age3 years
Last pushSep 27, 2026
Tracked files625
Lines of code55.9K
Checkout size31 MB

Lines by language: Python 39.8K, JSON 12K, Markdown 3,602, CSS 119, YAML 101, Shell 91.

Questions

Is Krita AI Diffusion free?

Yes. The plugin is GPL-3.0 and free, Krita is free, and generating on your own GPU costs nothing. The author also runs an optional cloud service at interstice.cloud for people without a capable GPU, with its own pricing. Models keep their own licences, and some limit commercial use.

What GPU do I need for Krita AI Diffusion?

The README recommends an NVIDIA card with at least 6 GB of VRAM; with less, or with no GPU, generation takes very long or fails for lack of memory. Larger models such as Flux need more memory than Stable Diffusion 1.5 or XL.

Does Krita AI Diffusion need ComfyUI?

Yes, ComfyUI is the engine, but you do not have to set it up yourself. The plugin's Configure screen can install and manage a local server, or you can connect it to an existing ComfyUI install, local or remote, as long as it has the required extensions and models.


This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.