Remote Code Execution Vulnerability in ToolJet by ToolJet
CVE-2026-55413

9.4CRITICAL

Key Information:

Vendor

Tooljet

Status
Vendor
CVE Published:
25 June 2026

What is CVE-2026-55413?

ToolJet, an open-source platform for creating internal tools and AI workflows, has a vulnerability that allows authenticated users with builder roles to overwrite a globally-shared marketplace plugin. This allows for the insertion of malicious JavaScript, which executes server-side with full Node.js access whenever a user queries that plugin. The vulnerability poses both a remote code execution risk and a potential supply-chain compromise for the entire ToolJet environment. This issue is resolved in version 3.20.178-lts.

Affected Version(s)

ToolJet < 3.20.178-lts

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.