Intel

AIKIDO-2026-10470

windmill-cli is vulnerable to Improper Authorization

Improper AuthorizationGHSA-jwg4-v3cj-rvfm

75

High Risk

This Affects:

JSwindmill-cli
1.561.0 - 1.674.1
Fixed in 1.674.2

TL;DR

Affected versions of this package are vulnerable to improper authorization when accessing secrets across workspaces. The affected endpoints perform incomplete workspace and permission validation, allowing a user with access to one workspace to reference identifiers belonging to another workspace. This insufficient authorization check can allow attackers to access metadata or resources they should not be permitted to view, resulting in cross-workspace information disclosure and unauthorized access.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

windmill-cli is vulnerable to Improper Authorization in versions 1.561.0 - 1.674.1.

How to fix this

Upgrade the windmill-cli library to a patch version.