Tooljet

Tooljet

15 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 11.08.2026 15:02:13
  • Zuletzt bearbeitet 13.08.2026 15:20:05

ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.207, the ToolJet Database HTTP API in server/src/modules/tooljet-db/controller.ts authorizes operations agai...

  • EPSS 0.17%
  • Veröffentlicht 08.07.2026 15:08:19
  • Zuletzt bearbeitet 09.07.2026 19:40:42

ToolJet is an open-source low-code platform for building internal tools. Prior to 3.20.180, ToolJet's render preview deployment workflow interpolates github.event.comment.body directly into a bash conditional in a run step, allowing any GitHub user w...

  • EPSS 0.13%
  • Veröffentlicht 25.06.2026 16:08:14
  • Zuletzt bearbeitet 25.06.2026 19:16:42

ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.1780-lts, the authenticated endpoint POST /api/data-sources/decrypt returns the decrypted plaintext for any ...

  • EPSS 0.19%
  • Veröffentlicht 25.06.2026 16:07:13
  • Zuletzt bearbeitet 25.06.2026 19:16:42

ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.178-lts, there's an SSRF in the RestAPI data source component. The RestAPI data source executes HTTP request...

  • EPSS 0.26%
  • Veröffentlicht 25.06.2026 16:03:40
  • Zuletzt bearbeitet 25.06.2026 19:16:42

ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.178-lts, any authenticated user with builder role (free tier) can overwrite a globally-shared marketplace pl...

Exploit
  • EPSS 1.04%
  • Veröffentlicht 26.04.2023 16:15:09
  • Zuletzt bearbeitet 09.07.2026 01:17:24

Tooljet v1.6 does not properly handle missing values in the API, allowing attackers to arbitrarily reset passwords via a crafted HTTP request.

Exploit
  • EPSS 0.48%
  • Veröffentlicht 26.04.2023 16:15:09
  • Zuletzt bearbeitet 09.07.2026 01:17:24

A cross-site scripting (XSS) vulnerability in ToolJet v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comment Body component.

Exploit
  • EPSS 0.75%
  • Veröffentlicht 22.11.2022 03:15:14
  • Zuletzt bearbeitet 21.11.2024 07:34:36

Unrestricted file size limit can lead to DoS in tooljet/tooljet <1.27 by allowing a logged in attacker to upload profile pictures over 2MB.

Exploit
  • EPSS 0.83%
  • Veröffentlicht 07.10.2022 11:15:09
  • Zuletzt bearbeitet 21.11.2024 07:19:28

Account Takeover :: when see the info i can see the hash pass i can creaked it ............... Account Takeover :: when see the info i can see the forgot_password_token the hacker can send the request and changed the pass

Exploit
  • EPSS 0.88%
  • Veröffentlicht 28.09.2022 09:15:09
  • Zuletzt bearbeitet 21.11.2024 07:19:20

Just like in the previous report, an attacker could steal the account of different users. But in this case, it's a little bit more specific, because it is needed to be an editor in the same app as the victim.