Security: appsmithorg/appsmith
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Git Widget Name Path Traversal Enables Server-Side Arbitrary JSON File WriteGHSA-r553-q33m-v7pf published
Jun 12, 2026 by wyattwalterHigh -
Caddy admin API exposed without authenticationGHSA-8jvv-gwqg-6vjc published
Jun 12, 2026 by wyattwalterCritical -
SSRF in REST API / GraphQL datasource plugins via insufficient host denylistGHSA-m23h-pvf3-2m7p published
Jun 12, 2026 by wyattwalterHigh -
Cross-application partial export leaks private actions and JS collections by mixing an authorized applicationId with an unrelated pageIdGHSA-9xfc-9f97-x524 published
Jun 10, 2026 by subrata71Moderate -
Broken Object-Level Authorization in PUT /api/v1/pages/{pageId}/dependencyMap Allows Unauthorized Cross-Workspace ModificationGHSA-q4p7-j55w-5mjm published
Jun 12, 2026 by wyattwalterHigh -
Unauthenticated Access to Full OpenAPI DocumentationGHSA-v6jh-fx3m-7xhw published
Jun 23, 2026 by subrata71Moderate -
RCE via Supervisord XML-RPC Admin Interface Exposed via /supervisor Caddy RouteGHSA-v49v-673j-g4vj published
Jun 12, 2026 by wyattwalterHigh -
Configuration-dependent origin validation bypass in password reset and email verification link generationGHSA-j9gf-vw2f-9hrw published
May 21, 2026 by subrata71High -
SSRF via `POST /api/v1/admin/send-test-email` — JavaMail Bypasses WebClient IP FilterGHSA-vvxf-f8q9-86gh published
Apr 17, 2026 by subrata71Moderate -
RCE via Newline Injection in `PUT /api/v1/admin/env` + Shell Sourcing of docker.envGHSA-xfvv-ggvq-pchh published
Apr 17, 2026 by subrata71High