Incorrect Default Permissions in Windmill Product by Windmill Labs
CVE-2026-47107
What is CVE-2026-47107?
Windmill prior to version 1.703.2 is vulnerable due to an incorrect default permissions setup in nsjail sandbox configuration files. This issue arises because the /etc directory is bind-mounted without the necessary read-write restrictions. As a result, authenticated users can write arbitrary entries to critical files such as /etc/hosts, /etc/resolv.conf, and /etc/ssl/certs/ca-certificates.crt during script executions within the sandbox environment. This vulnerability can be exploited by attackers to introduce persistent poisoned entries that affect subsequent script executions on the same worker pod. Consequently, adversaries may redirect hostnames, intercept DNS queries, conduct transparent HTTPS man-in-the-middle attacks, and access WM_TOKEN JWTs, potentially allowing them workspace-admin access to victim workspaces across different tenants.
Affected Version(s)
windmill 0
windmill 0 < 1.703.2
windmill f8467f38c8a053117ce62f96684cfb15ef792f08
