windmill-cli is vulnerable to Improper Authentication
72
High Risk
The Zoom challenge handler previously accepted attacker-controlled plainToken values and could be abused as a signing oracle, enabling attackers to obtain valid signatures for forged request bodies. The fix adds strict validation of plainToken format (rejecting colon-containing or overly long tokens), blocking the crafted token format required for the abuse.
You are affected if you are using a version that falls within the vulnerable range and if you use Zoom challenge/webhook signing.
windmill-cli is vulnerable to Improper Authentication in versions 1.479.0 - 1.714.0.
Upgrade the windmill-cli library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant