Windmill Project maintains a low-code workflow and automation platform with a focused product footprint, and its reported vulnerabilities center on path-traversal weaknesses that can arise in file-handling and resource-access logic. Treat this as a compact vendor profile; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Windmill Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-29059HIGH Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to version 1.603.3, an unauthenticated path traversal vulnerability | Mar 6, 2026 | 7.5 | 42 | NO | YES |
CVE-2026-22683HIGH Windmill versions 1.56.0 through 1.614.0 contain a missing authorization vulnerability that allows users with the Operator role to perform prohibited entity creation and modificati | Apr 7, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-33881HIGH Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Workspace environment variable values are interpolated into JavaScript st | Mar 27, 2026 | 7.2 | 23 | NO | NO |
CVE-2022-31519CRITICAL The Lukasavicus/WindMill repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | Jul 11, 2022 | 9.3 | 23 | NO | NO |
Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Versions 1.634.6
and below allow non-admin users to obtain Slack OAuth c | Feb 20, 2026 | 2.7 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Windmill Project.
Media articles that mention a CVE ID that affects a product developed by Windmill Project — matched by CVE ID, not by vendor name.