Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 14 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Windmill
Windmill windmill |
|
| CPEs | cpe:2.3:a:windmill:windmill:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Windmill
Windmill windmill |
|
| Metrics |
cvssV3_1
|
Tue, 07 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
ssvc
|
Mon, 09 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Windmill-labs
Windmill-labs windmill |
|
| Vendors & Products |
Windmill-labs
Windmill-labs windmill |
Fri, 06 Mar 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to version 1.603.3, an unauthenticated path traversal vulnerability exists in Windmill's get_log_file endpoint "(/api/w/{workspace}/jobs_u/get_log_file/{filename})". The filename parameter is concatenated into a file path without sanitization, allowing an attacker to read arbitrary files on the server using ../ sequences. This issue has been patched in version 1.603.3. | |
| Title | Windmill: SUPERADMIN_SECRET (rarely used) can be accessed publicly | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-07T13:16:12.488Z
Reserved: 2026-03-03T17:50:11.244Z
Link: CVE-2026-29059
Updated: 2026-03-09T20:01:38.640Z
Status : Analyzed
Published: 2026-03-06T08:16:26.437
Modified: 2026-04-14T17:48:25.300
Link: CVE-2026-29059
No data.
OpenCVE Enrichment
Updated: 2026-04-15T20:00:06Z