Security · 2h ago
Hackers Exploit Windmill Path Traversal Flaw to Read Server Files
A high-severity path traversal vulnerability (CVE-2026-29059, CVSS 7.5) in open-source developer platform Windmill is being actively exploited. The flaw allows unauthenticated attackers to read arbitrary server files via the get_log_file endpoint. VulnCheck reported the exploitation, urging users to patch immediately.
Meridian48 take
The attack underscores how even niche developer tools become prime targets once a vulnerability is public, especially when authentication is bypassed.
Read the full reporting
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication →
The Hacker News
windmillpath-traversal