← Back

Uipath

uipath

6 CVEs • 69 products

Products (69)

Click to collapse
Toggle
Orchestrator
orchestrator
Assistant
assistant
App Studio
app_studio
Uipath/ap Chat
uipath/ap-chat
Uipath/auth
uipath/auth
Uipath/cli
uipath/cli
Uipath/common
uipath/common
Uipath/robot
uipath/robot
Uipath/vss
uipath/vss

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
16Abhishake1
AgentworkhqAntoinebcx+13 more
171Agentwork Cli
Beproduct/nestjs AuthCmux Agent Mcp+168 more
May 29, 2026
May 12, 2026
N/A· v4
9.6 CRITICAL· v3
N/A· v2
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC t...Show more
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The attacker chained three known vulnerability classes — a pull_request_target "Pwn Request" misconfiguration, GitHub Actions cache poisoning across the fork↔base trust boundary, and runtime memory extraction of the OIDC token from the Actions runner process — to publish credential-stealing malware under a trusted identity. Each affected package received exactly two malicious versions, published a few minutes apart.Show less
1Uipath
1App Studio
Nov 21, 2024
Dec 14, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in UiPath App Studio 21.4.4. There is a persistent XSS vulnerability in the file-upload functionality for uploading icons when attempting to create new Apps. An attacker with minimal privileges in...Show more
An issue was discovered in UiPath App Studio 21.4.4. There is a persistent XSS vulnerability in the file-upload functionality for uploading icons when attempting to create new Apps. An attacker with minimal privileges in the application can build their own App and upload a malicious file containing an XSS payload, by uploading an arbitrary file and modifying the MIME type in a subsequent HTTP request. This then allows the file to be stored and retrieved from the server by other users in the same organization.Show less
1Uipath
1Assistant
Nov 21, 2024
Dec 14, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in UiPath Assistant 21.4.4. User-controlled data supplied to the --process-start argument of the URI handler for uipath-assistant:// is not correctly encoded, resulting in attacker-controlled cont...Show more
An issue was discovered in UiPath Assistant 21.4.4. User-controlled data supplied to the --process-start argument of the URI handler for uipath-assistant:// is not correctly encoded, resulting in attacker-controlled content being injected into the error message displayed (when the injected content does not match an existing process). A determined attacker could leverage this to execute JavaScript in the context of the Electron application.Show less
1Uipath
1Assistant
Nov 21, 2024
Dec 14, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget argument of the URI handler for uipath-assistant://. This allows an attacker to execute code on a vic...Show more
UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget argument of the URI handler for uipath-assistant://. This allows an attacker to execute code on a victim's machine or capture NTLM credentials by supplying a networked or WebDAV file path.Show less
1Uipath
1Orchestrator
Nov 21, 2024
Aug 8, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
UiPath Orchestrator before 2018.3.4 allows CSV Injection, related to the Audit export, Robot log export, and Transaction log export features.
1Uipath
1Orchestrator
Nov 21, 2024
Apr 11, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
UiPath Orchestrator through 2018.2.4 allows any authenticated user to change the information of arbitrary users (even administrators) leading to privilege escalation and remote code execution.