UiPath's vulnerability profile centers on its robotic process automation platform, which spans orchestration, automation studio, and process assistant components widely deployed in enterprise workflow environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and have an elevated tendency toward confirmed in-the-wild exploitation; the recurring weakness classes—including embedded malicious code, external resource reference, output escaping failures, and cross-site scripting—reflect both the integration-heavy nature of RPA tooling and the web-facing automation interfaces that sit in sensitive business process paths. Defenders should prioritize UiPath advisories and treat exposed orchestrator and studio instances as high-value remediation targets; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Uipath over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-45321CRITICAL On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated | May 12, 2026 | 9.6 | 79 | YES | NO |
CVE-2021-44041CRITICAL UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget argument of the URI handler for uipath-assistant://. This all | Dec 14, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-44042CRITICAL An issue was discovered in UiPath Assistant 21.4.4. User-controlled data supplied to the --process-start argument of the URI handler for uipath-assistant:// is not correctly encode | Dec 14, 2021 | 9.8 | 29 | NO | NO |
CVE-2018-17305HIGH UiPath Orchestrator through 2018.2.4 allows any authenticated user to change the information of arbitrary users (even administrators) leading to privilege escalation and remote cod | Apr 11, 2019 | 8.8 | 28 | NO | NO |
CVE-2021-44043MEDIUM An issue was discovered in UiPath App Studio 21.4.4. There is a persistent XSS vulnerability in the file-upload functionality for uploading icons when attempting to create new Apps | Dec 14, 2021 | 5.4 | 19 | NO | NO |
CVE-2018-19855MEDIUM UiPath Orchestrator before 2018.3.4 allows CSV Injection, related to the Audit export, Robot log export, and Transaction log export features. | Aug 8, 2019 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Uipath.
Media articles that mention a CVE ID that affects a product developed by Uipath — matched by CVE ID, not by vendor name.