VYPR

Windmill

by Windmill

Source repositories

CVEs (11)

  • CVE-2026-23696CriApr 7, 2026
    risk 0.59cvss 9.9epss 0.16

    Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership management functionality that allows authenticated attackers to inject SQL through the owner parameter. An attacker can use the injection to read sensitive data…

  • CVE-2026-22683HigApr 7, 2026
    risk 0.50cvss 8.8epss 0.03

    Windmill versions 1.56.0 through 1.614.0 contain a missing authorization vulnerability that allows users with the Operator role to perform prohibited entity creation and modification actions via the backend API. Although Operators are documented and priced as unable to create or…

  • CVE-2026-29059HigMar 6, 2026
    risk 0.49cvss 7.5epss 0.03

    Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to version 1.603.3, an unauthenticated path traversal vulnerability exists in Windmill's get_log_file endpoint "(/api/w/{workspace}/jobs_u/get_log_file/{filename})".…

  • CVE-2026-47107HigMay 19, 2026
    risk 0.46cvss 8.1epss 0.00

    Windmill prior to 1.703.2 contains an incorrect default permissions vulnerability in nsjail sandbox configuration files where /etc is bind-mounted without read-write restrictions, allowing authenticated users to write arbitrary entries to /etc/hosts, /etc/resolv.conf, and…

  • CVE-2026-72541MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace member to overwrite any resource type schema via the update_resource_type endpoint. The endpoint omits the administrator permission check that the corresponding…

  • CVE-2026-72539MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    An information disclosure vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace member to read legacy ownerless draft scripts that contain plaintext resource credentials. Drafts with a null owner email bypass ACL enforcement and are returned…

  • CVE-2026-33881HigMar 27, 2026
    risk 0.40cvss 7.2epss 0.00

    Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Workspace environment variable values are interpolated into JavaScript string literals without escaping single quotes in the NativeTS executor. A workspace admin who sets a…

  • CVE-2026-72542MedAug 11, 2026
    risk 0.35cvss 5.4epss 0.00

    A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows authenticated operators to write job progress and read job metrics for any job in the workspace regardless of ownership. The job_metrics handlers accept no authorization extractor, bypassing…

  • CVE-2026-54136medJul 10, 2026
    risk 0.26cvss epss

    ### Summary A resource-scoped API token can read script contents outside its allowed path scope via `GET /api/w/{workspace}/scripts/list_search`. This appears to be a remaining variant of the scoped-token authorization class previously addressed for other endpoints. The…

  • CVE-2024-8462LowSep 5, 2024
    risk 0.17cvss 3.7epss 0.01

    A vulnerability was found in Windmill 1.380.0. It has been classified as problematic. Affected is an unknown function of the file backend/windmill-api/src/users.rs of the component HTTP Request Handler. The manipulation leads to improper restriction of excessive authentication…

  • CVE-2026-26964LowFeb 20, 2026
    risk 0.11cvss 2.7epss 0.00

    Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Versions 1.634.6 and below allow non-admin users to obtain Slack OAuth client secrets, which should only be accessible to workspace administrators. The GET…