Remote Code Execution Vulnerability in ToolJet by ToolJet
CVE-2026-55413
9.4CRITICAL
What is CVE-2026-55413?
ToolJet, an open-source platform for creating internal tools and AI workflows, has a vulnerability that allows authenticated users with builder roles to overwrite a globally-shared marketplace plugin. This allows for the insertion of malicious JavaScript, which executes server-side with full Node.js access whenever a user queries that plugin. The vulnerability poses both a remote code execution risk and a potential supply-chain compromise for the entire ToolJet environment. This issue is resolved in version 3.20.178-lts.
Affected Version(s)
ToolJet < 3.20.178-lts
