Executive brief
Windmill, an open-source developer platform, contained a security flaw in its script execution environment. This vulnerability allowed users with script execution permissions to modify critical system files like network and security certificate configurations. Because these changes could persist on the underlying server, an attacker could intercept data or gain administrative access to other customers' workspaces on the same platform.
Technical details
Windmill's nsjail sandbox configuration incorrectly handled bind-mounts for the /etc directory. While /etc was mounted read-only, Kubernetes submounts for /etc/hosts, /etc/resolv.conf, and /etc/hostname remained writable because nsjail's read-only remount is non-recursive. An authenticated attacker could execute a script to modify these files, persisting 'poisoned' DNS or SSL entries on the long-lived worker pod. This allows for Man-in-the-Middle (MITM) attacks against subsequent jobs from other tenants on the same pod, potentially leading to the interception of WM_TOKEN JWTs and full workspace-admin escalation. The issue is fixed in version 1.703.2 by adding explicit read-only binds for these specific files.
Affected products
- Windmill Labs Windmill < 1.703.2
Timeline
- 2026-05-17: patched: Fix merged in PR #9194 and released in v1.703.2
- 2026-05-19: disclosed: CVE-2026-47107 published
References
- https://github.com/windmill-labs/windmill/commit/f8467f38c8a053117ce62f96684cfb15ef792f08
- https://github.com/windmill-labs/windmill/pull/9194
- https://github.com/windmill-labs/windmill/releases/tag/v1.703.2
- https://www.vulncheck.com/advisories/windmill-incorrect-default-permissions-in-nsjail-configuration