CVE-2026-33881 identifies a code injection vulnerability in Windmill, an open-source developer platform, affecting versions prior to 1.664.0. This flaw allows a workspace administrator to inject arbitrary JavaScript into NativeTS scripts by leveraging unescaped environment variable values. Rated High severity (CVSS 7.3), the vulnerability has a network attack vector and low complexity, enabling a highly privileged attacker to achieve high impact on confidentiality, integrity, and availability within the affected workspace. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion, with a very low EPSS score reflecting a low likelihood of future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.664.0CPE matchmatch criteria | cpe:2.3:a:windmill:windmill:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.