# CVE-2026-29059: Windmill - Path Traversal

> Live exploitation tracking for CVE-2026-29059 by the CrowdSec Live Exploit Tracker, built from real-world attack data crowdsourced from CrowdSec's global network.

Page: https://tracker.crowdsec.net/cves/CVE-2026-29059

## Key facts

- **Exploitation phase:** Background Noise. Continuous low-level scanning or exploitation attempts are observed, mostly opportunistic and automated.
- **CVSS score:** 6.9
- **Public exploit available:** Yes
- **Affected products:** Windmill-Labs Windmill
- **Weaknesses:** CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))
- **Tags:** web_application, enterprise_software

## Description

Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to version 1.603.3, an unauthenticated path traversal vulnerability exists in Windmill's get_log_file endpoint "(/api/w/{workspace}/jobs_u/get_log_file/{filename})". The filename parameter is concatenated into a file path without sanitization, allowing an attacker to read arbitrary files on the server using ../ sequences. This issue has been patched in version 1.603.3.

## CrowdSec analysis

[CVE-2026-29059](https://euvd.enisa.europa.eu/vulnerability/CVE-2026-29059) is a path traversal vulnerability in Windmill, an open-source developer platform, affecting versions prior to 1.603.3. This flaw allows unauthenticated attackers to exploit the get_log_file endpoint by manipulating the filename parameter, enabling unauthorized reading of arbitrary files on the server. Attackers could leverage this vulnerability to access sensitive information and potentially aid in further attacks against the system. The issue has been addressed in version 1.603.3.

CrowdSec has been tracking this vulnerability and its exploits since 1st of July 2026.

CrowdSec network data shows that most actors exploiting CVE-2026-29059 rely on broad, untargeted scans with minimal filtering. The activity is largely automated and opportunistic in nature.
In addition, according to the CrowdSec network, attack volume against CVE-2026-29059 has dipped slightly compared to the previous week. Although still commonly targeted, the decline suggests a cooling-off period. Long-term relevance remains, but attention is waning.

Attackers exploit the `/api/w/_/jobs_u/get_log_file/` and related endpoints by supplying path traversal sequences (e.g., `..%2F..%2F..%2Fetc%2Fpasswd`) in the URL to read arbitrary files from the server without authentication.

## Timeline

- 2026-03-06: CVE Published. CVE-2026-29059 is published to NVD.
- 2026-07-01: Rule Released. CrowdSec releases a rule to detect CVE-2026-29059 exploitation attempts against the CrowdSec Network.
- 2026-07-02: CrowdSec First Seen. CrowdSec observes in-the-wild exploitation of CVE-2026-29059 for the first time.

## References

- https://github.com/Chocapikk/Windfall
- https://github.com/windmill-labs/windmill/security/advisories/GHSA-24fr-44f8-fqwg
- https://github.com/windmill-labs/windmill/releases/tag/v1.603.3
- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-29059.yaml

## Live exploitation data

The [Live Exploit Tracker page](https://tracker.crowdsec.net/cves/CVE-2026-29059) follows observed exploitation activity for CVE-2026-29059. [Request an API key](https://tracker.crowdsec.net/request-api-key) for full access to its exploitation timeline, attacking IP addresses and blocklists.
