Vulnerability  ·  2026-06-27

ToolJet AI Agent Platform — Authenticated Builder Can Overwrite Global Marketplace Plugin with Arbitrary Server-Side JavaScript (RCE)

VulnerabilityHigh impactGlobalCVE-2026-55413
ToolJet prior to 3.20.178-lts allows any authenticated user with a builder role to overwrite a globally-shared marketplace plugin with arbitrary JavaScript that executes server-side. Because marketplace plugins are shared across the platform, a single low-privileged builder can compromise all users and all connected data sources, AI workflows, and agent integrations system-wide.
ToolJet is an AI-native platform for building agentic workflows and internal tools. Server-side JavaScript execution via a marketplace plugin gives an attacker full backend access, including all database credentials, API keys for AI services, and the ability to manipulate or exfiltrate every agent workflow and connected data source on the instance.
An authenticated user with a builder role (available on the free tier) can send a crafted API request to overwrite a globally-shared marketplace plugin with arbitrary JavaScript. The malicious JavaScript executes server-side with ToolJet's backend privileges, enabling full server compromise and lateral movement to all connected data sources and AI agent configurations.
ToolJet < 3.20.178-lts
Upgrade to ToolJet 3.20.178-lts or later. Advisory: https://github.com/ToolJet/ToolJet/security/advisories/GHSA-jgmf-cw3v-r98x
Sources
Tenable CVE-2026-55413NVD CVE-2026-55413GitHub Advisory GHSA-jgmf-cw3v-r98x
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →