Intel

AIKIDO-2026-10918

windmill-client is vulnerable to Information Disclosure

Information Disclosure Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published 2 days ago

30

Low Risk

This Affects:

JSwindmill-client
1.629.0 - 1.708.0
Fixed in 1.709.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package allowed resource-scoped tokens to bypass per-resource restrictions when calling listing endpoints such as list_search_resources, list_resources, list_names, and list_variables, exposing paths and values from unrelated workspace resources. An attacker with a token limited to one resource could abuse these endpoints to enumerate and read other stored data, including integration credentials, API keys, database connection strings, and other non-secret or secret values, because authorization was enforced only at the route level and not per returned row.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

windmill-client is vulnerable to Information Disclosure in versions 1.629.0 - 1.708.0.

How to fix this

Upgrade the windmill-client library to the patch version.