PatchSiren

activepieces CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM activepieces CVE published 2026-08-11

CVE-2026-73084

CVE-2026-73084 debrief based on the supplied source corpus. The vulnerability is a medium-severity issue in Activepieces that allows for JavaScript injection via the /api/redirect OAuth callback endpoint. This could lead to potential execution of arbitrary JavaScript in the Activepieces origin, access to victim's session tokens, and authenticated API calls on the victim's behalf. Defenders should prioriti [truncated]

HIGH activepieces CVE published 2026-08-11

CVE-2026-73083

CVE-2026-73083 is a high-severity vulnerability in Activepieces, an open-source AI workflow automation platform. Prior to version 0.80.0, an authenticated user can create a Code step to access environment secrets, read or write files, and reach internal services due to improper sandboxing. This issue allows attackers to bypass security restrictions and access sensitive data. Activepieces users and adminis [truncated]

MEDIUM activepieces CVE published 2026-08-11

CVE-2026-73082

CVE-2026-73082 is a vulnerability in Activepieces, an open-source AI workflow automation platform. An authenticated user can cause the Activepieces server to connect to internal services, cloud metadata endpoints, or arbitrary external hosts and probe network reachability from the Activepieces host due to a lack of URL validation or SSRF protection in the POST /api/v1/projects/:projectId/mcp-server/valida [truncated]

HIGH activepieces CVE published 2026-08-11

CVE-2026-73081

CVE-2026-73081 is a high-severity vulnerability in Activepieces, an open-source AI workflow automation platform. An authenticated user with permission to create or edit a flow can execute arbitrary commands during compilation, potentially leading to unauthorized access and data breaches. This vulnerability allows attackers to execute commands as the worker process user, read and write the worker filesyste [truncated]

MEDIUM activepieces CVE published 2026-07-16

CVE-2026-53536

CVE-2026-53536 is a vulnerability in the Activepieces open source AI workflow automation platform. Prior to version 0.83.0, the /v1/step-files/signed download endpoint did not properly verify the token's audience and lacked a null-check on the decoded fileId, allowing any caller with a valid Activepieces JWT to receive a step-file belonging to another tenant. This issue allows for unauthorized access to s [truncated]

MEDIUM activepieces CVE published 2026-07-16

CVE-2026-53535

CVE-2026-53535 is a MEDIUM severity vulnerability in Activepieces, an open-source AI workflow automation platform. The git-sync feature clones a user-configured Git repository into a temporary directory on the server. Prior to version 0.82.0, two weaknesses allowed writes to escape the intended workspace and land on arbitrary paths on the host filesystem. An attacker with WRITE_PROJECT_RELEASE permission [truncated]

LOW activepieces CVE published 2026-06-21

CVE-2026-12813

CVE-2026-12813 is a server-side request forgery (SSRF) vulnerability detected in activepieces up to version 0.83.0. The vulnerability affects the handleUrlFile function in the /packages/server/engine/src/lib/variables/processors/file.ts file. This issue allows for remote exploitation and has a publicly available exploit. The CVSS score is 2.1, indicating a low severity. The vendor, Unknown Vendor, was con [truncated]