Windmill is a workflow automation and scripting platform with a narrow product focus; the durable signal centers on application-layer vulnerabilities spanning information disclosure, code injection, path traversal, and authorization bypass. These weakness classes reflect the inherent risks of dynamic code execution and file-system access in automation frameworks. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Windmill over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-29059HIGH Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to version 1.603.3, an unauthenticated path traversal vulnerability | Mar 6, 2026 | 7.5 | 42 | NO | YES |
CVE-2026-22683HIGH Windmill versions 1.56.0 through 1.614.0 contain a missing authorization vulnerability that allows users with the Operator role to perform prohibited entity creation and modificati | Apr 7, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-33881HIGH Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Workspace environment variable values are interpolated into JavaScript st | Mar 27, 2026 | 7.2 | 23 | NO | NO |
CVE-2022-31519CRITICAL The Lukasavicus/WindMill repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | Jul 11, 2022 | 9.3 | 23 | NO | NO |
Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Versions 1.634.6
and below allow non-admin users to obtain Slack OAuth c | Feb 20, 2026 | 2.7 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Windmill.
Media articles that mention a CVE ID that affects a product developed by Windmill — matched by CVE ID, not by vendor name.