ToolJet
Products
1- ToolJet15 CVEsnpm
Recent CVEs
15| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-27978 | Hig | 0.49 | 7.5 | 0.01 | Apr 26, 2023 | Tooljet v1.6 does not properly handle missing values in the API, allowing attackers to arbitrarily reset passwords via a crafted HTTP request. | ||
| CVE-2022-27979 | Med | 0.35 | 5.4 | 0.00 | Apr 26, 2023 | A cross-site scripting (XSS) vulnerability in ToolJet v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comment Body component. | ||
| CVE-2022-4111 | Med | 0.35 | 6.5 | 0.01 | Nov 22, 2022 | Unrestricted file size limit can lead to DoS in tooljet/tooljet <1.27 by allowing a logged in attacker to upload profile pictures over 2MB. | ||
| CVE-2026-73068 | Med | 0.31 | 5.9 | 0.00 | Aug 11, 2026 | ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.207, the ToolJet Database HTTP API in server/src/modules/tooljet-db/controller.ts authorizes operations against the :organizationId URL… | ||
| CVE-2026-54344 | Med | 0.00 | 4.7 | 0.00 | Jul 8, 2026 | ToolJet is an open-source low-code platform for building internal tools. Prior to 3.20.180, ToolJet's render preview deployment workflow interpolates github.event.comment.body directly into a bash conditional in a run step, allowing any GitHub user who can comment on an open… | ||
| CVE-2026-55413 | Cri | 0.00 | — | 0.00 | Jun 25, 2026 | ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.178-lts, any authenticated user with builder role (free tier) can overwrite a globally-shared marketplace plugin with arbitrary… | ||
| CVE-2026-55412 | Hig | 0.00 | 8.3 | 0.00 | Jun 25, 2026 | ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.178-lts, there's an SSRF in the RestAPI data source component. The RestAPI data source executes HTTP requests server-side, and its… | ||
| CVE-2026-55411 | Med | 0.00 | 6.8 | 0.00 | Jun 25, 2026 | ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.1780-lts, the authenticated endpoint POST /api/data-sources/decrypt returns the decrypted plaintext for any credential whose… | ||
| CVE-2022-3422 | Hig | 0.00 | 7.5 | 0.01 | Oct 7, 2022 | Account Takeover :: when see the info i can see the hash pass i can creaked it ............... Account Takeover :: when see the info i can see the forgot_password_token the hacker can send the request and changed the pass | ||
| CVE-2022-3348 | Med | 0.00 | 4.9 | 0.01 | Sep 28, 2022 | Just like in the previous report, an attacker could steal the account of different users. But in this case, it's a little bit more specific, because it is needed to be an editor in the same app as the victim. | ||
| CVE-2022-3019 | Hig | 0.00 | 8.8 | 0.01 | Aug 29, 2022 | The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that we can see (bruteforcing comment id's might also be an option but I wouldn't count on it, since it would take a long time to find a valid one). | ||
| CVE-2022-2631 | Hig | 0.00 | 8.8 | 0.01 | Aug 2, 2022 | Improper Access Control in GitHub repository tooljet/tooljet prior to v1.19.0. | ||
| CVE-2022-2037 | Hig | 0.00 | 8.0 | 0.01 | Jun 9, 2022 | Excessive Attack Surface in GitHub repository tooljet/tooljet prior to v1.16.0. | ||
| CVE-2022-23068 | Med | 0.00 | 5.4 | 0.01 | May 18, 2022 | ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name field while inviting a new user which will be reflected in the invitational e-mail. | ||
| CVE-2022-23067 | Hig | 0.00 | 8.8 | 0.01 | May 18, 2022 | ToolJet versions v0.5.0 to v1.2.2 are vulnerable to token leakage via Referer header that leads to account takeover . If the user opens the invite link/signup link and then clicks on any external links within the page, it leaks the password set token/signup token in the referer… |
- risk 0.49cvss 7.5epss 0.01
Tooljet v1.6 does not properly handle missing values in the API, allowing attackers to arbitrarily reset passwords via a crafted HTTP request.
- risk 0.35cvss 5.4epss 0.00
A cross-site scripting (XSS) vulnerability in ToolJet v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comment Body component.
- risk 0.35cvss 6.5epss 0.01
Unrestricted file size limit can lead to DoS in tooljet/tooljet <1.27 by allowing a logged in attacker to upload profile pictures over 2MB.
- risk 0.31cvss 5.9epss 0.00
ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.207, the ToolJet Database HTTP API in server/src/modules/tooljet-db/controller.ts authorizes operations against the :organizationId URL…
- risk 0.00cvss 4.7epss 0.00
ToolJet is an open-source low-code platform for building internal tools. Prior to 3.20.180, ToolJet's render preview deployment workflow interpolates github.event.comment.body directly into a bash conditional in a run step, allowing any GitHub user who can comment on an open…
- risk 0.00cvss —epss 0.00
ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.178-lts, any authenticated user with builder role (free tier) can overwrite a globally-shared marketplace plugin with arbitrary…
- risk 0.00cvss 8.3epss 0.00
ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.178-lts, there's an SSRF in the RestAPI data source component. The RestAPI data source executes HTTP requests server-side, and its…
- risk 0.00cvss 6.8epss 0.00
ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.1780-lts, the authenticated endpoint POST /api/data-sources/decrypt returns the decrypted plaintext for any credential whose…
- risk 0.00cvss 7.5epss 0.01
Account Takeover :: when see the info i can see the hash pass i can creaked it ............... Account Takeover :: when see the info i can see the forgot_password_token the hacker can send the request and changed the pass
- risk 0.00cvss 4.9epss 0.01
Just like in the previous report, an attacker could steal the account of different users. But in this case, it's a little bit more specific, because it is needed to be an editor in the same app as the victim.
- risk 0.00cvss 8.8epss 0.01
The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that we can see (bruteforcing comment id's might also be an option but I wouldn't count on it, since it would take a long time to find a valid one).
- risk 0.00cvss 8.8epss 0.01
Improper Access Control in GitHub repository tooljet/tooljet prior to v1.19.0.
- risk 0.00cvss 8.0epss 0.01
Excessive Attack Surface in GitHub repository tooljet/tooljet prior to v1.16.0.
- risk 0.00cvss 5.4epss 0.01
ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name field while inviting a new user which will be reflected in the invitational e-mail.
- risk 0.00cvss 8.8epss 0.01
ToolJet versions v0.5.0 to v1.2.2 are vulnerable to token leakage via Referer header that leads to account takeover . If the user opens the invite link/signup link and then clicks on any external links within the page, it leaks the password set token/signup token in the referer…