PT-2026-28548 · Windmill · Windmill

Published

2026-03-27

·

Updated

2026-04-08

·

CVE-2026-33881

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Windmill versions prior to 1.664.0
Description Windmill, a developer platform for internal code including APIs, background jobs, workflows, and UIs, is affected by a code injection issue. Workspace environment variable values are interpolated into JavaScript string literals without proper escaping of single quotes within the NativeTS executor. A workspace administrator can exploit this by setting a custom environment variable containing a single quote (') to inject arbitrary JavaScript code. This injected code will then execute within every NativeTS script in that workspace. The issue resides in the worker.rs file and is not related to sandboxing or NSJAIL.
Recommendations Update to version 1.664.0 or later.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-33881
GHSA-8Q8J-MM3G-5C2Q

Affected Products

Windmill