CVE-2026-85057High· 8.7▾ TwilightZITADEL is an open source identity management platform. From 3.0.0 until 3.4.13 and 4.16.1, ZITADEL Actions V1 enables the goja Node-compatible require() registry without restricting its filesystem source loader. An organization Action a…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 47.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
ZITADEL is an open source identity management platform. From 3.0.0 until 3.4.13 and 4.16.1, ZITADEL Actions V1 enables the goja Node-compatible require() registry without restricting its filesystem source loader. An organization Action author with ORG_OWNER, org.action.write, and org.flow.write permissions can run JavaScript at OIDC, SAML, and login-flow trigger points and load files readable by the ZITADEL server process. This can disclose mounted configuration and secrets, including credentials stored through ZITADEL_FIRSTINSTANCE_LOGINCLIENTPATPATH or ZITADEL_FIRSTINSTANCE_MACHINEKEYPATH, and recovered bootstrap credentials can enable escalation from an organization administrator to an instance administrator. The issue affects Actions V1, and host command execution is not established. This issue is fixed in versions 3.4.13 and 4.16.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/zitadel/zitadel < 1.80.0-v2.20.0.20260717062331-baf6ed501b68Patched in:
github.com/zitadel/zitadel 1.80.0-v2.20.0.20260717062331-baf6ed501b68Connected by shared product, vendor, weakness, or advisory.
CVE-2026-85056High· 8.2ZITADEL is an open source identity management platform
CVE-2026-55670LowZITADEL: Cross-Tenant User Leakage via Recycled Identifiers
CVE-2026-76081Medium· 5.5ZITADEL is an open source identity management platform
CVE-2026-56668High· 8.1ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange
CVE-2023-47111High· 7.3ZITADEL race condition in lockout policy execution
CVE-2023-22492Medium· 5.9Zitadel RefreshToken invalidation vulnerability