Altium Workflow Engine Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in the Altium Workflow Engine. This issue arises from inadequate server-side input sanitization in the workflow form submission APIs. As a result, a regular authenticated user can inject arbitrary JavaScript into the workflow data. When an administrator accesses the affected workflow, the injected script executes in the administrator's browser context. This exploitation can lead to privilege escalation, allowing the creation of new administrator accounts, theft of session tokens, and execution of administrative actions.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, with the injected JavaScript executing in the context of an administrator's browser. This could lead to privilege escalation, including the creation of new administrator accounts, theft of session tokens, and the ability to perform administrative actions.

Added: Jan 15, 2026, 11:21 PM
Updated: Jan 15, 2026, 11:21 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.4
exploitability
4.6
remediation
0.0
relevance
2.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.