VYPR
Critical severity9.8NVD Advisory· Published Dec 14, 2021· Updated Jun 17, 2026

CVE-2021-44041

CVE-2021-44041

Description

UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget argument of the URI handler for uipath-assistant://. This allows an attacker to execute code on a victim's machine or capture NTLM credentials by supplying a networked or WebDAV file path.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Uipath/Assistantllm-create3 versions
    <=21.4.4+ 2 more
    • (no CPE)range: <=21.4.4
    • (no CPE)
    • cpe:2.3:a:uipath:assistant:21.4.4:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.