ToolJet patches three flaws: cross-tenant credential decryption, SSRF and plugin RCE
Three vulnerabilities (CVE-2026-55411/55412/55413) disclosed in ToolJet, the open-source platform for internal tools, workflows and AI agents, allowed any authenticated user to decrypt other organisations' data-source secrets, reach cloud metadata endpoints via SSRF to steal Azure managed identity tokens, and overwrite shared marketplace plugins with server-side JavaScript for RCE and supply-chain compromise. All are fixed in versions 3.20.1780-lts and 3.20.178-lts.
Disclosed 25 June 2026 · Record updated 13 September 2026
Impact
Any authenticated user, including free-tier users, could decrypt other tenants' data-source credentials, exfiltrate Azure managed identity tokens for the AKS production cluster via SSRF, and execute arbitrary Node.js code server-side by overwriting a globally shared marketplace plugin.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-55411
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-55412
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-55413
