windmill
windmill-labs- Software type
- —
- Catalog vulnerabilities
- 5
Severity across 5 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 5 analyzed records
A short verification protects source data and prevents automated AI requests.
The GCVE catalog currently lists 5 vulnerability records affecting windmill.
Among the 5 records analyzed by CyStack, 2 are High or Critical and 0 appear in the CISA KEV catalog.
Compare the version you run with each vulnerability and the provider guidance below. The data only includes records analyzed so far.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan
| CVE | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-54136Windmill: Resource-scoped API tokens can read script contents outside their allowed path via scripts/list_search | Exploitation statusNot known exploited | FixYes | Published08/20/2026 | SeverityMedium |
CVE-2026-47107Windmill < 1.703.2 Incorrect Default Permissions in nsjail Configuration | Exploitation statusPublic exploit | FixYes | Published05/19/2026 | SeverityHigh |
CVE-2026-33881Windmill: Rogue Workspace Admins can inject code via unescaped workspace environment variable interpolation in NativeTS executor | Exploitation statusPublic exploit | FixNot confirmed | Published03/27/2026 | SeverityHigh |
CVE-2026-29059Windmill: SUPERADMIN_SECRET (rarely used) can be accessed publicly | Exploitation statusPublic exploit | FixYes | Published03/06/2026 | SeverityMedium |
CVE-2026-26964Windmill Exposes Workspace Slack OAuth Client Secrets to Non-Admin Workspace Members | Exploitation statusNot known exploited | FixYes | Published02/19/2026 | SeverityLow |