Browse all 5 CVE security advisories affecting windmill-labs. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-54136 | Windmill: Resource-scoped API tokens can read script contents outside their allowed path via scripts/list_search — windmill CWE-863 | 5.1 | Medium | 2026-08-20 |
| CVE-2026-47107 | Windmill < 1.703.2 Incorrect Default Permissions in nsjail Configuration — windmill CWE-276 | 8.1 | High | 2026-05-19 |
| CVE-2026-33881 | Windmill: Rogue Workspace Admins can inject code via unescaped workspace environment variable interpolation in NativeTS executor — windmill CWE-94 | 4.8 | - | 2026-03-27 |
| CVE-2026-29059 | Windmill: SUPERADMIN_SECRET (rarely used) can be accessed publicly — windmill CWE-22 | 7.5 | - | 2026-03-06 |
| CVE-2026-26964 | Windmill Exposes Workspace Slack OAuth Client Secrets to Non-Admin Workspace Members — windmill CWE-200 | 2.7 | Low | 2026-02-19 |
This page lists every published CVE security advisory associated with windmill-labs. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.