CVE-2026-54136 | Windmill Labs up to 1.714.x Resource-scoped API Token list_search list_search_scripts hard-coded credentials

SecurityVulns

A vulnerability described as problematic has been identified in Windmill Labs Windmill up to 1.714.x. Affected by this issue is the function list_search_scripts of the file /api/w/{workspace}/scripts/list_search of the component Resource-scoped API Token. Executing a manipulation can lead to hard-coded credentials.

This vulnerability is registered as CVE-2026-54136. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More