Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Palantir — Vulnerabilities & Security Advisories 47

Browse all 47 CVE security advisories affecting Palantir. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Palantir Technologies primarily develops software platforms for data integration, analysis, and decision-making, serving government agencies and large enterprises. With forty-seven recorded Common Vulnerabilities and Exposures (CVEs), the company’s historical attack surface has frequently involved remote code execution, cross-site scripting, and privilege escalation flaws. These vulnerabilities often stem from complex web interfaces and backend data processing components, allowing attackers to potentially bypass authentication or execute arbitrary commands. Notable security characteristics include the inherent risks associated with handling sensitive, classified, or proprietary data, which makes successful exploitation particularly damaging. While specific major public breaches are less documented compared to consumer tech firms, the high-value nature of its client base necessitates rigorous security postures. The recurring nature of these CVEs highlights the challenges of securing large-scale, integrated data ecosystems against sophisticated threat actors seeking access to critical information infrastructure.

CVE ID Title CVSS Severity Published
CVE-2025-68609 Authentication bypass in Aries due to misconfiguration — com.palantir.aries:aries CWE-305 6.6 Medium 2026-01-22
CVE-2025-62487 Under certain configurations, file artifacts uploaded to the Dossier and Slides apps did not inherit security markings of their parent artifact. This lack of security markings could lead to unintended access to the uploaded files. — com.palantir.acme:gotham-default-apps-bundle CWE-863 3.5 Low 2026-01-09
CVE-2023-30971 Gaia unauthenticated endpoints — com.palantir.acme.gaia:gaia CWE-592 6.8 Medium 2025-12-19
CVE-2024-49587 Glutton V1 endpoints missing authentication — com.palantir.gotham:glutton CWE-305 9.1 Critical 2025-12-19
CVE-2025-53710 Network boundaries not respected in certain Foundry namespaces. — com.palantir.compute:compute-service CWE-653 7.5 High 2025-12-18
CVE-2025-64400 Insufficient permission checks when pre-enrolling users Summary — com.palantir.controlpanel:control-panel CWE-284 4.1 Medium 2025-12-18
CVE-2025-53709 Access control issues impacting secure-upload service — com.palantir.secupload:secure-upload CWE-285 5.4 Medium 2025-07-10
CVE-2024-49589 Foundry artifacts denial of service — com.palantir.artifacts:artifacts CWE-770 6.5 Medium 2025-02-18
CVE-2024-49581 Access control issue impacting RV backed objects — com.palantir.gotham:external-artifacts CWE-862 6.5 Medium 2024-12-02
CVE-2024-49588 Multiple authenticated SQL injections in oracle-sidecar — com.palantir.srx.prometheus.sls-oracle-sidecar:sls-oracle-sidecar CWE-89 6.8 Medium 2024-11-21
CVE-2023-30968 Stored XSS in gaia — com.palantir.acme.gaia:gaia CWE-434 6.8 Medium 2024-03-12
CVE-2023-22836 In cases where a multi-tenant stack user is operating Foundry’s Linter service, and the user changes the linter name from the default value, the renamed value may be visible to the rest of the stack’s tenants. — com.palantir.skywise:guardian CWE-862 3.5 Low 2024-01-29
CVE-2023-30970 Gotham table and Forward App Path traversal — com.palantir.gotham:blackbird-witchcraft CWE-36 6.5 Medium 2024-01-29
CVE-2023-30954 Gotham Video Broken Authentication — com.palantir.video:video-application-server CWE-285 2.7 Low 2023-11-15
CVE-2023-30967 Gotham Orbital Simulator path traversal — com.palantir.meta:orbital-simulator CWE-22 9.8 Critical 2023-10-25
CVE-2023-30969 Palantir Tiles missing authentication on API endpoints — com.palantir.tiles:tiles CWE-284 8.2 High 2023-10-25
CVE-2023-30961 Palantir Gotham UI bug that could lead to incorrect data classification — com.palantir.acme:gotham-fe-bundle CWE-710 6.5 Medium 2023-09-26
CVE-2023-30959 Stored XSS via javascript URI in Apollo Change Requests comment — com.palantir.apollo:autopilot CWE-84 4.1 Medium 2023-09-26
CVE-2023-30962 Stored XSS in cerberus attachments — com.palantir.acme.cerberus:cerberus CWE-434 6.8 Medium 2023-09-12
CVE-2023-30952 Foundry Issues reporterPath phishing by parameter injection — com.palantir.foundry:foundry-frontend CWE-20 5.0 Medium 2023-08-03
CVE-2023-30950 CVE-2023-30950 — com.palantir.campaigns:campaigns CWE-290 6.5 Medium 2023-08-03
CVE-2023-30958 DOM XSS in Developer mode dashboard via redirect GET parameter — com.palantir.foundry:foundry-frontend CWE-83 4.7 Medium 2023-08-03
CVE-2023-30951 CVE-2023-30951 — com.palantir.magritte:magritte-rest-source-bundle CWE-611 6.3 Medium 2023-08-03
CVE-2023-30949 CVE-2023-30949 — com.palantir.slate:slate CWE-1173 4.3 Medium 2023-07-26
CVE-2023-30956 IDOR in Foundry Comments allows retrieval of attachments — com.palantir.comments:comments CWE-639 5.3 Medium 2023-07-10
CVE-2023-30960 Insecure Direct Object Reference (IDOR) in Foundry job-tracker — com.palantir.foundry.jobtracker:job-tracker CWE-639 4.3 Medium 2023-07-10
CVE-2023-30963 Stored XSS in Foundry Slate Query Dropdown menu — com.palantir.foundry:foundry-frontend CWE-82 5.4 Medium 2023-07-10
CVE-2023-22835 Denial of Service in Foundry Issues — com.palantir.foundry:foundry-frontend CWE-20 7.7 High 2023-07-10
CVE-2023-30946 Issues notification metadata lacks authorization — com.palantir.issues:issues CWE-420 3.5 Low 2023-06-29
CVE-2023-30955 Foundry workspace-server Developer Mode Authorization Bypass — com.palantir.workspace:workspace CWE-602 4.3 Medium 2023-06-29

This page lists every published CVE security advisory associated with Palantir. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.