Junglewise Threat Intelligence

CVE-2026-54136: Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to 1.715.0, a resource-scop

CVE-2026-54136 · Severity: medium · CVSS 4 · Published 2026-08-20

Vendors: Windmill Labs, crates.io.

Executive brief

Windmill is an open-source developer platform for automation and internal tools. A security flaw allows API tokens that are supposed to be restricted to specific folders or scripts to instead view the source code of any script within the entire workspace. This could lead to the exposure of sensitive business logic, internal automation details, or accidentally hardcoded credentials.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in the `GET /api/w/{workspace}/scripts/list_search` endpoint of Windmill. While the route-level middleware validates the token's domain and action (e.g., `scripts:read`), it fails to enforce the resource/path segment of the scope (e.g., `f/allowed/*`). The handler executes a SQL query that retrieves all scripts in a workspace without applying per-row filtering against the token's specific path restrictions. An attacker with a valid scoped API token can exploit this to retrieve the `path` and `content` of scripts they are not authorized to access. The issue is addressed in version 1.715.0.

Affected products

  • Windmill Labs windmill-api <= 1.714.1

Timeline

  • 2026-06-03: disclosed: Initial report to vendor
  • 2026-07-10: advisory: GitHub Advisory published
  • 2026-07-10: patched: Fix confirmed in version 1.715.0

References