windmill-client is vulnerable to Information Disclosure
30
Low Risk
Affected versions of this package allowed resource-scoped tokens to bypass per-resource restrictions when calling listing endpoints such as list_search_resources, list_resources, list_names, and list_variables, exposing paths and values from unrelated workspace resources. An attacker with a token limited to one resource could abuse these endpoints to enumerate and read other stored data, including integration credentials, API keys, database connection strings, and other non-secret or secret values, because authorization was enforced only at the route level and not per returned row.
You are affected if you are using a version that falls within the vulnerable range.
windmill-client is vulnerable to Information Disclosure in versions 1.629.0 - 1.708.0.
Upgrade the windmill-client library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant