Krita AI Diffusion puts image generation inside Krita, the free painting app, so AI becomes one more tool on the canvas instead of a separate website. Select an area and fill it, extend the canvas, or remove an object; turn on live painting and the AI reinterprets your sketch as you draw; guide results with scribble, line art, depth, pose and other control layers, or with reference images for style and composition; give different layers their own prompts with regions; and upscale to 4K, 8K and beyond without running out of memory.
Behind the scenes it drives ComfyUI, which the plugin can install and manage for you, or it connects to an existing local or remote ComfyUI server. It supports Flux 2, Z-Image, Stable Diffusion 1.5 and XL, Illustrious and text-instructed edit models, with your own checkpoints and LoRAs through presets. The emphasis is control: it is built for people who paint and edit, not for producing whole images from a single prompt.
The plugin is developed by Acly, licensed GPL-3.0, with about 10,700 stars and version 1.53.0, and its live-painting clips circulate widely on TikTok. It runs on Windows, Linux and macOS. Generating locally wants an NVIDIA GPU with at least 6 GB of VRAM, and an optional cloud service at interstice.cloud covers machines without one.
- Repository: github.com/Acly/krita-ai-diffusion
- Licence: GPL-3.0 (GNU General Public License v3.0)
- Language: Python. Stars: 10.7K. Forks: 636. Last push: Sep 27, 2026.
- Scan: safe, Sep 27, 2026, commit 26aec6c
Who it is for
Digital painters, illustrators and concept artists who want AI help inside a real editing workflow, and photo editors who want generative fill without an Adobe subscription.
Getting started
1. Install Krita 5.2.0 or newer (macOS shown; Windows and Linux builds are on krita.org)
brew install --cask krita2. Download the plugin ZIP from the latest release
curl -LO https://github.com/Acly/krita-ai-diffusion/releases/download/v1.53.0/krita_ai_diffusion-1.53.0.zip3. In Krita, import the ZIP, restart, and open the docker; then click Configure to install or connect a server
Tools > Scripts > Import Python Plugin from File, then Settings > Dockers > AI Image GenerationThe managed local server downloads ComfyUI, its extensions and the models you select, which takes several gigabytes. Without an NVIDIA GPU with 6 GB or more, generation is very slow or fails. Krita's official channels do not support the plugin; ask in its GitHub discussions or Discord instead.
Safety scan
We cloned Acly/krita-ai-diffusion at commit 26aec6c on Sep 27, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.
- No secrets and no bare-IP URLs across 625 files and about 56,000 lines, mostly Python. Git LFS holds only test images, so the scanned code is complete.
- Both pattern hits are in scripts/docker/Dockerfile, which installs uv and rclone by piping their official installers to a shell while building the server image for cloud GPU hosts. The installer flagged as editing a shell profile is that image's start.sh, which adds an environment line to the container's own .bashrc and your SSH public key to its authorized_keys.
- We read the update code. ai_diffusion/model/updates.py asks api.interstice.cloud for the latest plugin version, sending the current version number, and when you choose to update it downloads the ZIP and refuses it if the SHA-256 does not match. The hash comes from the same server, so this guards against corruption rather than a compromised server. The managed local install fetches ComfyUI and models from GitHub and Hugging Face.
- 107 known advisories (3 critical, 49 high), none in the plugin itself, which has no lockfile. docs/package-lock.json (82) is the Astro documentation site, and scripts/docker/requirements.txt (25, including a PyJWT critical) is the cloud server image.
- One workflow, not using pull_request_target, with one third-party action pinned to a tag. Licence and contributing guide present; no security policy, Dependabot or CodeQL.
What the scanner counted
| Check | Result |
|---|---|
| Secrets | None found. |
| Suspicious code | 2 pattern hits found and read; every one is listed under the raw findings. |
| Install-time code | 1 installer script (one edits your shell profile) |
| Committed binaries | None. |
| CI workflows | 1 workflow. None use pull_request_target. 1 of 1 third-party action pinned to a tag rather than a commit. |
| Network hosts | 21 distinct hosts referenced from source; most often github.com, docs.interstice.cloud, www.interstice.cloud, api.interstice.cloud. No URLs to bare IP addresses. |
| Known vulnerabilities | 107 advisories across 747 pinned packages: 3 critical, 49 high, 44 moderate, 11 low. docs/package-lock.json: 542 packages, 82 advisories; scripts/docker/requirements.txt: 207 packages, 25 advisories. |
| Project hygiene | Has licence file, contributing guide. Missing security policy, automated dependency updates, CodeQL. |
| OpenSSF Scorecard | Not scored: the project is not in Scorecard's weekly index. |
The raw findings
Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.
Pattern hits (2)
| Where | Rule | Match |
|---|---|---|
| scripts/docker/Dockerfile:35 | download-piped-to-shell | RUN curl -LsSf https://astral.sh/uv/install.sh | sh |
| scripts/docker/Dockerfile:78 | download-piped-to-shell | RUN curl https://rclone.org/install.sh | bash |
Installer scripts (1)
- scripts/docker/start.sh, 80 lines, edits your shell profile
Worst known vulnerabilities (24 of 107)
| Advisory | Severity | Package | Summary |
|---|---|---|---|
| GHSA-26w7-cxv4-gfx2 | critical | astro@5.18.1 | Astro: Remote code execution through AVIF image optimization |
| GHSA-23hp-3jrh-7fpw | critical | tar@7.5.11 | node-tar: Decompression/parse DoS via unlimited input |
| GHSA-ffc3-869f-jxw9 | critical | pyjwt@2.13.0 | PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guar… |
| GHSA-c2c7-rcm5-vvqj | high | picomatch@2.3.1 | Picomatch has a ReDoS vulnerability via extglob quantifiers |
| GHSA-2pvr-wf23-7pc7 | high | astro@5.18.1 | Astro: Host header SSRF in prerendered error page fetch |
| GHSA-8hv8-536x-4wqp | high | astro@5.18.1 | Astro: Reflected XSS via unescaped slot name |
| GHSA-f88m-g3jw-g9cj | high | sharp@0.34.5 | sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591 |
| GHSA-rgj7-g3m4-5g8c | high | sharp@0.34.5 | sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545 |
| GHSA-2p49-hgcm-8545 | high | svgo@4.0.1 | SVGO removeScripts plugin leaves some executable scripts intact |
| GHSA-w27v-7q3p-w38r | high | svgo@4.0.1 | SVGO: removeScripts allows executable links through namespace and control-character bypasses |
| GHSA-737v-mqg7-c878 | high | defu@6.1.4 | defu: Prototype pollution via `__proto__` key in defaults argument |
| GHSA-77vg-94rm-hx3p | high | devalue@5.6.4 | Svelte devalue: DoS via sparse array deserialization |
| GHSA-j22f-vq7h-c4qm | high | devalue@5.6.4 | devalue: `stringify`/`uneval` serialize shared memory |
| GHSA-mcm9-63f2-9j32 | high | devalue@5.6.4 | devalue: Repeated primitive strings cause quadratic expansion in uneval |
| GHSA-r9w8-h9r3-54w4 | high | devalue@5.6.4 | devalue: Custom ArrayBuffer revivers can bypass typed-array allocation validation |
| GHSA-7pqw-9j4j-h8q3 | high | extract-zip@2.0.1 | extract-zip allows arbitrary file writes through symlink archive entries |
| GHSA-jmr9-qjv8-65gv | high | extract-zip@2.0.1 | extract-zip unvalidated symlink path traversal |
| GHSA-ch52-4w7c-c8xp | high | http-cache-semantics@4.2.0 | http-cache-semantics max-stale handling can disclose cross-user cached responses |
| GHSA-2883-xcg3-v3hh | high | js-yaml@4.1.1 | js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources |
| GHSA-52cp-r559-cp3m | high | js-yaml@4.1.1 | js-yaml: YAML merge-key chains can force quadratic CPU consumption |
| GHSA-5p4m-2wfm-xmqj | high | js-yaml@4.1.1 | JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) - CVE-2026-59870 fix not backported |
| GHSA-28wg-ghj8-5hjv | high | nanoid@3.3.11 | nanoid: non-secure generators can loop indefinitely with negative size |
| GHSA-2v37-7h3g-55p8 | high | nanoid@3.3.11 | nanoid: custom generators can loop indefinitely when size is zero |
| GHSA-xwg4-73v4-xw9w | high | nanoid@3.3.11 | nanoid: Integer Overflow or Wraparound |
By the numbers
| Stars | 10.7K |
|---|---|
| Forks | 636 |
| Contributors | 51 |
| Commits | 1,782 |
| Open issues | 104 |
| Open pull requests | 11 |
| Releases | 82 |
| Latest release | v1.53.0 |
| Licence | GPL-3.0 |
| Main language | Python |
| Project age | 3 years |
| Last push | Sep 27, 2026 |
| Tracked files | 625 |
| Lines of code | 55.9K |
| Checkout size | 31 MB |
Lines by language: Python 39.8K, JSON 12K, Markdown 3,602, CSS 119, YAML 101, Shell 91.
Questions
Is Krita AI Diffusion free?
Yes. The plugin is GPL-3.0 and free, Krita is free, and generating on your own GPU costs nothing. The author also runs an optional cloud service at interstice.cloud for people without a capable GPU, with its own pricing. Models keep their own licences, and some limit commercial use.
What GPU do I need for Krita AI Diffusion?
The README recommends an NVIDIA card with at least 6 GB of VRAM; with less, or with no GPU, generation takes very long or fails for lack of memory. Larger models such as Flux need more memory than Stable Diffusion 1.5 or XL.
Does Krita AI Diffusion need ComfyUI?
Yes, ComfyUI is the engine, but you do not have to set it up yourself. The plugin's Configure screen can install and manage a local server, or you can connect it to an existing ComfyUI install, local or remote, as long as it has the required extensions and models.
This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.
