windmill-client is vulnerable to Path Traversal
57
Medium Risk
The Windmill client writes raw-app files and runnables to disk during sync pull by joining server-provided file keys and runnable ids onto the local app folder path. The keys are not validated, so a .. sequence in a raw-app file key or runnable id escapes the app folder. Pulling a workspace whose raw-app content is controlled by another party can write files to arbitrary locations on the machine running the sync. The fix resolves each path and rejects any that escape the target app folder.
You are affected if you are using a version that falls within the vulnerable range and you run the CLI sync pull against a workspace whose raw-app file keys or runnable ids can be influenced by an untrusted party.
windmill-client is vulnerable to Path Traversal in versions 1.587.0 - 1.794.1.
Upgrade the windmill-client library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.