Vulnerabilities > Uipath > Assistant > 21.4.4

DATE CVE VULNERABILITY TITLE RISK
2021-12-14 CVE-2021-44041 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Uipath Assistant 21.4.4
UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget argument of the URI handler for uipath-assistant://.
network
low complexity
uipath CWE-610
critical
10.0
2021-12-14 CVE-2021-44042 Improper Encoding or Escaping of Output vulnerability in Uipath Assistant 21.4.4
An issue was discovered in UiPath Assistant 21.4.4.
network
low complexity
uipath CWE-116
7.5