7.5

CVE-2026-29059

Medienbericht

Windmill: SUPERADMIN_SECRET (rarely used) can be accessed publicly

Remote code execution in Nextcloud Flow via vulnerable Windmill version

Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to version 1.603.3, an unauthenticated path traversal vulnerability exists in Windmill's get_log_file endpoint "(/api/w/{workspace}/jobs_u/get_log_file/{filename})". The filename parameter is concatenated into a file path without sanitization, allowing an attacker to read arbitrary files on the server using ../ sequences. This issue has been patched in version 1.603.3.
Mögliche Gegenmaßnahme
Flow: The only workaround is to disable the Flow app and make sure the container is turned off and does not restart
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WindmillWindmill Version < 1.603.3
Weitere Schwachstelleninformationen
SystemNextcloud App
Produkt Flow
Version >= 1.0.0, < 1.3.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.58% 0.832
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
security-advisories@github.com 6.9 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
13.04.2026 16:21
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
09.03.2026 09:01
https://github.com/windmill-labs/windmill/security/advisories/GHSA-24fr-44f8-fqwg
Vendor Advisory
https://github.com/windmill-labs/windmill/releases/tag/v1.603.3
Release Notes
https://github.com/Chocapikk/Windfall
Product
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-g7vj-98x3-qvjf
Third Party Advisory