Zapier's vulnerability footprint centers on Code by Zapier, a code-execution platform that allows users to run custom logic within automation workflows, with observed issues concentrating on improper permission assignment for critical resources. This narrow, application-specific exposure reflects the access-control demands inherent to a multi-tenant code-execution environment where privilege boundaries between user contexts are essential to isolation. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zapier over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-28802CRITICAL Code by Zapier before 2022-08-17 allowed intra-account privilege escalation that included execution of Python or JavaScript code. In other words, Code by Zapier was providing a cus | Sep 21, 2022 | 9.9 | 30 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zapier.
Media articles that mention a CVE ID that affects a product developed by Zapier — matched by CVE ID, not by vendor name.