Home / Security updates / UIPS-2021-002 - Security Advisory - UiPath Assistant - Remote Code Execution
UIPS-2021-002 - Security Advisory - UiPath Assistant - Remote Code Execution
Security updates detail rendered from /security-updates/upd_c8f349377db1f7ad.
Overview
| ID | upd_c8f349377db1f7ad |
| Collection | Security Updates |
| Provider | SafeBase |
| Company | UiPath |
| URL | - |
| Counts | - |
| Updated | - |
Raw record
| Field | Value |
|---|---|
| id | upd_c8f349377db1f7ad |
| providerId | safebase |
| organizationId | org_33d000fdc8a62017 |
| trustCenterId | tc_7d7ee18589030c52 |
| title | UIPS-2021-002 - Security Advisory - UiPath Assistant - Remote Code Execution |
| message | **Title: UiPath Assistant - Remote Code Execution** Publish Date: Dec 7, 2021 Version: 1.0 General Information Affected Versions: Assistant 2021.4 to 2021.4.5 Assistant 2021.10 to 2021.10.3 CVSS Score: 8.3 Details: An issue was fixed in the processing of user-supplied widget identification command line parameters. The functionality allowed users to develop and run Assistant widgets from the command line. It was possible for a malicious web page to open the desktop application and to inject a remote file location of a widget using a network share. *Links to release notes have been removed as no version is still in support when migrating this advisory to https://trust.uipath.com on November 21, 2025. Links below have been replaced with the latest version of each product affected.* [Latest Overall Version](https://download.uipath.com/UiPathStudio.msi) Suggested Actions Update to latest Assistant patches available: 2021.4 and 2021.10 The issue is not directly exploitable, it requires o |
| url | - |
| publishedAt | 2025-11-21 |
| source | {
"field": "statuspage/public/compliance-update",
"category": "vulnerabilities"
} |
| company | {
"id": "org_33d000fdc8a62017",
"name": "UiPath",
"domains": [
"trust.uipath.com",
"uipath.com"
]
} |
| trust_center | {
"id": "tc_7d7ee18589030c52",
"name": "UiPath",
"url": "https://trust.uipath.com",
"host": "trust.uipath.com"
} |
| provider | {
"id": "safebase",
"name": "SafeBase"
} |
| links | {
"self": "/v1/security-updates/upd_c8f349377db1f7ad",
"company": "/v1/companies/org_33d000fdc8a62017",
"trust_center": "/v1/trust-centers/tc_7d7ee18589030c52",
"provider": "/v1/providers/safebase"
} |
Get this page with API
Rendered from the bluedoor Trust Centers API. Reproduce it:
GET https://api.bluedoor.sh/trust-centers/v1/security-updates/upd_c8f349377db1f7adJSON