Intel

AIKIDO-2026-11052

windmill-cli is vulnerable to Improper Authentication

Improper Authentication Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published 2 days ago

72

High Risk

This Affects:

JSwindmill-cli
1.479.0 - 1.714.0
Fixed in 1.714.1
Are you affected? Scan for Free

TL;DR

The Zoom challenge handler previously accepted attacker-controlled plainToken values and could be abused as a signing oracle, enabling attackers to obtain valid signatures for forged request bodies. The fix adds strict validation of plainToken format (rejecting colon-containing or overly long tokens), blocking the crafted token format required for the abuse.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and if you use Zoom challenge/webhook signing.

Background info

windmill-cli is vulnerable to Improper Authentication in versions 1.479.0 - 1.714.0.

How to fix this

Upgrade the windmill-cli library to the patch version.