Back to news

Windmill Path Traversal Exploited in Wild; LG Moves to Purge Proxy Apps from Smart TVs

Active exploitation of an unauthenticated file-read flaw in Windmill and a sweeping LG crackdown on residential proxy apps signal a broadening attack surface for enterprise and consumer environments alike.

Windmill Path Traversal Exploited in Wild; LG Moves to Purge Proxy Apps from Smart TVs

What happened

Security researchers at VulnCheck confirmed active in-the-wild exploitation of CVE-2026-29059, a high-severity path traversal vulnerability in the open-source developer platform Windmill, rated 7.5 on the CVSS scale. The flaw resides in the platform's log-file retrieval endpoint, where an unsanitized filename parameter can be manipulated to navigate outside the intended directory and expose arbitrary server files — all without requiring any authentication. Separately, LG Electronics USA announced plans to suspend smart TV applications on its webOS store that silently enroll televisions as residential proxy nodes, routing third-party internet traffic through users' home connections. The decision followed published research showing that more than 42 percent of apps in the webOS catalog contained this proxy behavior.

Why it matters for your business

Organizations running self-hosted Windmill instances for workflow automation or internal tooling should treat CVE-2026-29059 as an immediate remediation priority: an unauthenticated attacker can harvest credentials, configuration files, or proprietary data without ever logging in. Engineering and security teams should audit internet-exposed Windmill deployments, apply vendor patches or restrict endpoint access at the network layer, and review logs for anomalous requests to the affected API path. The LG situation carries a different but equally serious implication — corporate networks that allow employees to connect personal smart TVs or use office TVs for conferencing may be inadvertently hosting proxy exit nodes, creating both bandwidth and compliance risks. Procurement and IT policies should be updated to account for IoT and smart TV device behavior, not just traditional endpoints.

What to watch next

For Windmill, the key question is whether the vendor's patch fully neutralizes the traversal vector or whether additional endpoint hardening is required — organizations should monitor the project's GitHub advisories and changelog closely. On the LG front, it remains to be seen how rigorously the company enforces the ban and whether competing smart TV platforms such as Samsung's Tizen or Google TV face similar scrutiny from regulators and researchers. Broader regulatory attention on IoT devices that secretly monetize consumer bandwidth could accelerate mandatory disclosure requirements across the consumer electronics industry.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp