Stackstorm is an automation and orchestration platform with a focused vulnerability footprint concentrated in its core product, which serves as a workflow engine for IT operations and security automation. The recurring weakness classes—cross-site scripting, authorization gaps, and logic-flow issues such as infinite loops—reflect the interaction of web-facing interfaces and stateful orchestration logic that characterize this automation platform. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Stackstorm over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-44657HIGH In StackStorm versions prior to 3.6.0, the jinja interpreter was not run in sandbox mode and thus allows execution of unsafe system commands. Jinja does not enable sandboxed mode b | Dec 15, 2021 | 8.8 | 27 | NO | NO |
CVE-2022-44009HIGH Improper access control in Key-Value RBAC in StackStorm version 3.7.0 didn't check the permissions in Jinja filters, allowing attackers to access K/V pairs of other users, potentia | Dec 6, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-28667HIGH StackStorm before 3.4.1, in some situations, has an infinite loop that consumes all available memory and disk space. This can occur if Python 3.x is used, the locale is not utf-8, | Mar 18, 2021 | 7.5 | 23 | NO | NO |
CVE-2022-43706MEDIUM Cross-site scripting (XSS) vulnerability in the Web UI of StackStorm versions prior to 3.8.0 allowed logged in users with write access to pack rules to inject arbitrary script or H | Dec 5, 2022 | 5.4 | 20 | NO | NO |
CVE-2018-20345MEDIUM Incorrect access control in StackStorm API (st2api) in StackStorm before 2.9.2 and 2.10.x before 2.10.1 allows an attacker (who has a StackStorm account and is authenticated agains | Dec 21, 2018 | 5.3 | 20 | NO | NO |
CVE-2019-9580MEDIUM In st2web in StackStorm Web UI before 2.9.3 and 2.10.x before 2.10.3, it is possible to bypass the CORS protection mechanism via a "null" origin value, potentially leading to XSS. | Mar 9, 2019 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Stackstorm.
Media articles that mention a CVE ID that affects a product developed by Stackstorm — matched by CVE ID, not by vendor name.