Intel

AIKIDO-2026-361443

windmill-client is vulnerable to Path Traversal

Path Traversal Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Yesterday

57

Medium Risk

This Affects:

JSwindmill-client
1.587.0 - 1.794.1
Fixed in 1.795.0
Are you affected? Scan for Free

TL;DR

The Windmill client writes raw-app files and runnables to disk during sync pull by joining server-provided file keys and runnable ids onto the local app folder path. The keys are not validated, so a .. sequence in a raw-app file key or runnable id escapes the app folder. Pulling a workspace whose raw-app content is controlled by another party can write files to arbitrary locations on the machine running the sync. The fix resolves each path and rejects any that escape the target app folder.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you run the CLI sync pull against a workspace whose raw-app file keys or runnable ids can be influenced by an untrusted party.

Background info

windmill-client is vulnerable to Path Traversal in versions 1.587.0 - 1.794.1.

How to fix this

Upgrade the windmill-client library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform