Browse all 3 CVE security advisories affecting windmill-labs. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-33881 | Windmill: Rogue Workspace Admins can inject code via unescaped workspace environment variable interpolation in NativeTS executor — windmillCWE-94 | 4.8 | - | 2026-03-27 |
| CVE-2026-29059 | Windmill: SUPERADMIN_SECRET (rarely used) can be accessed publicly — windmillCWE-22 | 7.5 | - | 2026-03-06 |
| CVE-2026-26964 | Windmill Exposes Workspace Slack OAuth Client Secrets to Non-Admin Workspace Members — windmillCWE-200 | 2.7 | Low | 2026-02-19 |
This page lists every published CVE security advisory associated with windmill-labs. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.