Metrics
Affected Vendors & Products
Tue, 19 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 19 May 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Windmill-labs
Windmill-labs windmill |
|
| Vendors & Products |
Windmill-labs
Windmill-labs windmill |
Tue, 19 May 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Windmill prior to 1.703.2 contains an incorrect default permissions vulnerability in nsjail sandbox configuration files where /etc is bind-mounted without read-write restrictions, allowing authenticated users to write arbitrary entries to /etc/hosts, /etc/resolv.conf, and /etc/ssl/certs/ca-certificates.crt from within script execution sandboxes. Attackers can exploit persistent poisoned entries across all subsequent script executions on the same worker pod to redirect hostnames, intercept DNS queries, perform transparent HTTPS man-in-the-middle attacks, and intercept WM_TOKEN JWTs to gain workspace-admin access to victim workspaces across tenants. | |
| Title | Windmill < 1.703.2 Incorrect Default Permissions in nsjail Configuration | |
| Weaknesses | CWE-276 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-19T18:36:27.927Z
Reserved: 2026-05-18T19:22:26.748Z
Link: CVE-2026-47107
Updated: 2026-05-19T18:36:23.336Z
Status : Deferred
Published: 2026-05-19T18:16:22.167
Modified: 2026-05-19T21:08:30.800
Link: CVE-2026-47107
No data.
OpenCVE Enrichment
Updated: 2026-05-19T19:30:12Z