Tartışma

Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

Başlatan The Hacker News · 22 Tem 2026 16:51 · 0 Görüntülenme · 0 Yanıtlar
Konuyu Açan #0
A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck.

The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill's "get_log_file" endpoint ("/api/w/{workspace}/jobs_u/get_log_file/{filename}").

"The filename parameter is concatenated into

Okumaya devam et...

Yanıt vermek için giriş yapmış olmalısınız.

0 alıntı seçildi