CVE-2026-55413: ToolJet - Marketplace Plugin Poisoning Enables Instance-Wide Remote Code Execution
ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.178-lts, any authenticated user with builder role (free tier) can overwrite a globally-shared marketplace plugin with arbitrary JavaScript that executes server-side with full Node.js access (require, process). The malicious code runs whenever any user on the instance triggers a query using that plugin — achieving both RCE and supply-chain compromise of the entire ToolJet deployment. This vulnerability is fixed in 3.20.178-lts.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ToolJetto a version that resolves this vulnerability.Fixed in 3.20.178-lts
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55413?
CVE-2026-55413 has a risk score of 85, indicating a high severity vulnerability.
How do I fix CVE-2026-55413?
To fix CVE-2026-55413, upgrade to ToolJet version 3.20.178-lts or later.
Who is affected by CVE-2026-55413?
Any authenticated user with a builder role on versions prior to 3.20.178-lts of ToolJet is affected by CVE-2026-55413.
What does CVE-2026-55413 allow an attacker to do?
CVE-2026-55413 allows an attacker to overwrite a globally-shared marketplace plugin, enabling instance-wide remote code execution.
What is the nature of the vulnerability described in CVE-2026-55413?
CVE-2026-55413 is categorized as a Code Injection vulnerability.