PT-2026-23658 · Windmill · Windmill
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Windmill versions prior to 1.603.3
Nextcloud Flow versions prior to 1.3.0
Description
An unauthenticated path traversal flaw exists in the Windmill developer platform. The issue occurs at the
/api/w/{workspace}/jobs u/get log file/{filename} endpoint, where the filename parameter is concatenated into a file path without proper sanitization. This allows an attacker to use ../ sequences to read arbitrary files on the server. Real-world incidents of active exploitation have been observed, where the flaw was used to leak credentials, access the SUPERADMIN SECRET, and in some cases, achieve root shell access and remote code execution. Path traversal is a technique used to access files and directories that are stored outside the web root folder.Recommendations
Update Windmill to version 1.603.3 or later.
Update Nextcloud Flow to version 1.3.0 or later.
Restrict access to the
/api/w/{workspace}/jobs u/get log file/{filename} endpoint to minimize the risk of exploitation.Exploit
Fix
RCE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windmill