Researchers disclosed a chain of critical vulnerabilities in the Windmill workflow automation platform and its Nextcloud Flow integration that can lead to unauthenticated remote code execution. The most severe issue, tracked as CVE-2026-29059, is a path traversal flaw affecting Windmill v1.309.0 through v1.603.2 and Nextcloud Flow v1.0.0 through v1.2.2, allowing attackers to read arbitrary files, steal secrets and tokens, and potentially gain root-level code execution. In Nextcloud Flow deployments, the risk was amplified because a public unauthenticated jobs_u endpoint was exposed through the proxy, enabling attacks without logging in.
A second flaw, described as an authenticated SQL injection affecting Windmill v1.276.0 through v1.603.2, allowed users with limited access to exfiltrate database contents, escalate privileges from operator to super_admin, and execute code. The reported exploit chain also leveraged plaintext Windmill credentials stored by Nextcloud Flow, access to PostgreSQL data, and theft of the Nextcloud AppAPI secret to compromise the broader Nextcloud environment; in some cases, host escape was possible where the Docker socket was mounted. Windmill said it fixed the issues in v1.603.3 and v1.615.0, while Nextcloud Flow addressed the bundled vulnerable version in v1.3.0 before later being deprecated in favor of an official Windmill integration.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Following remediation, Nextcloud Flow was later deprecated and replaced with an official Windmill integration. This marked the retirement of the affected third-party integration after the disclosed security issues.
A detailed public report explained how the flaws could be chained from unauthenticated path traversal to credential theft, PostgreSQL access, AppAPI secret recovery, and full Nextcloud compromise. It also documented authenticated privilege escalation from operator to super_admin and subsequent code execution in vulnerable Windmill deployments.
Nextcloud Flow addressed the vulnerable embedded Windmill component in version v1.3.0, ending exposure for versions v1.0.0 through v1.2.2. The integration had been particularly risky because it proxied a public unauthenticated endpoint and stored Windmill credentials in plaintext.
Windmill released fixes for the reported issues, with the path traversal flaw fixed in v1.603.3 and later remediation also referenced in v1.615.0. The affected ranges included Windmill versions from v1.309.0 through v1.603.2 for CVE-2026-29059 and from v1.276.0 through v1.603.2 for the SQL injection issue.
On 2026-01-10, researcher Chocapikk disclosed multiple vulnerabilities affecting Windmill and its Nextcloud Flow integration, including unauthenticated path traversal CVE-2026-29059 and an authenticated SQL injection issue. The disclosure described paths to credential theft, privilege escalation, and remote code execution, with Nextcloud Flow deployments especially exposed through a public proxied endpoint.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcechocapikk.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.