These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. A vulnerability in Windmill versions prior to 1.715.0 allows a resource-scoped API token to read script contents outside its allowed path scope through GET /api/w/{workspace}/scripts/list_search. The route-level scope middleware validated the token domain and action but did not enforce the resource/p [truncated]
A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows authenticated operators to write job progress and read job metrics for any job in the workspace regardless of ownership. The job_metrics handlers accept no authorization extractor, bypassing workspace-level access controls. This issue may expose sensitive job execution data and allow misleading progress injection. Users [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T12:17:39.470Z and has not been modified since then. This executive overview aims to provide a high-level understanding of the vulnerability and its potential impacts, helping organizations prioritize and plan their mitigation efforts effectively. The goal is to ensure that all relevant stakeholde [truncated]
The CVE-2026-72539 vulnerability is an information disclosure issue in Windmill Labs Windmill through version 1.783.0. This vulnerability allows any authenticated workspace member to read legacy ownerless draft scripts that contain plaintext resource credentials. These drafts, with a null owner email, bypass Access Control List (ACL) enforcement and are returned to any workspace member who queries the dra [truncated]
CVE-2026-47107 describes an incorrect default-permissions issue in Windmill's nsjail sandbox configuration. In affected versions before 1.703.2, /etc is bind-mounted without read-write restrictions, allowing authenticated users to alter files such as /etc/hosts, /etc/resolv.conf, and /etc/ssl/certs/ca-certificates.crt from within script execution sandboxes. Because those changes can persist across later e [truncated]
CVE-2026-23696 is a critical SQL injection vulnerability in Windmill CE and EE versions 1.276.0 through 1.603.2. The vulnerability is located in the folder ownership management functionality and allows authenticated attackers to inject SQL through the owner parameter. This type of vulnerability typically allows attackers to read sensitive data, execute arbitrary code, or elevate privileges. Administrators [truncated]