Stackstorm

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 8
    Known Exploited: 0
    0
    Critical Level Threats
    3
    High Level Threats
    5
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-85514

    StackStorm st2 API Key auth.py privileges management

    Last Modified: Sep 04, 2026
    Published: Sep 04, 2026

    CVE-2026-85513

    StackStorm st2 NoOp RBAC backend actionexecutions.py privileges management

    Last Modified: Sep 04, 2026
    Published: Sep 04, 2026

    CVE-2022-43706

    Cross-site scripting (XSS) vulnerability in the Web UI of StackStorm versions prior to 3.8.0 allowed logged in users with write access to pack rules to inject arbitrary script or HTML that may be executed in Web UI for other logged in users.

    Last Modified: Apr 24, 2025
    Published: Dec 05, 2022

    CVE-2022-44009

    Improper access control in Key-Value RBAC in StackStorm version 3.7.0 didn't check the permissions in Jinja filters, allowing attackers to access K/V pairs of other users, potentially leading to the exposure of sensitive Information.

    Last Modified: Apr 24, 2025
    Published: Dec 05, 2022

    CVE-2021-44657

    In StackStorm versions prior to 3.6.0, the jinja interpreter was not run in sandbox mode and thus allows execution of unsafe system commands. Jinja does not enable sandboxed mode by default due to backwards compatibility. Stackstorm now sets sandboxed mode for jinja by default.

    Last Modified: Nov 21, 2024
    Published: Dec 15, 2021
    Items Per Page
    Stackstorm Vulnerabilities & Security CVEs | CVE-DB