UiPath Logo

Trust Center

Start your security review
View & download sensitive information
ControlK

Overview

Welcome to UiPath Trust Center. Our commitment to data privacy and security is embedded in every part of our business. Use this Trust Center to learn about our security posture and request access to our security documentation. UiPath maintains a comprehensive information security management system and engages independent auditors to provide industry-standard certifications and attestations.

• You can subscribe for updates and share the page with the icons on left of this page.
• CVE or vulnerabilities and reporting a security issue can be entered at the bottom in contact support or report issue links.

For UiPath legal information please visit - UiPath Trust Portal – Built for Secure Agentic Scale (https://www.uipath.com/legal/trust-and-security).

Documents

REPORTS2024 Pentest Report
If you need help using this Trust Center, please contact us.
Contact support
If you think you may have discovered a vulnerability, please send us a note.
Report issue

Trust Center Updates

Security Advisory - ArgoCD Vulnerability Mitigation

Copy link
Vulnerabilities

UiPath Security Advisory - ArgoCD

UiPath is recommending all Automation Suite customers implement the documented mitigation linked below to address a High Severity Vulnerability in ArgoCD as soon as possible. This RCE vulnerability does not have a CVE number and ArgoCD has not released a patch to address it.

Automation Suite 2.2510 Documentation
Automation Suite 24.10 Documentation
Automation Suite 23.10 Documentation

TanStack NPM Compromise

Incidents

UiPath security engineering and independently Wiz Security have confirmed that all of the compromised UiPath NPM packages have a bug rendering the malware non-functional.

All UiPath customers should be aware that these NPM packages if downloaded pose no risk of malware.

Update - Malicious versions of NPM packages were available on registry.npmjs.org for approximately 1 hour before deprecation and ~6 hours before unpublish completed. No production systems, identity infrastructure, or customer data were accessed by the attacker based on information currently available to UiPath. We have provided a list of all affected packages that could have potentially been downloaded and executed by customers.

We have released a Full Public Postmortem of this event which can be found here

UiPath is aware of the NPM supply chain compromise affecting TanStack. We are continuing to investigate, but believe that the impact to UiPath has been successfully contained. Please see the attached Post Mortem Report.

CVE-2025-55315 Trust Center update

Vulnerabilities

October 27, 2025
Trust Center - Public
Update October 27, 2025

UiPath has deployed remediation patches to all affected services in the UiPath Automation Cloud and UiPath Automation Cloud Public Sector environments. Investigation is ongoing for all other services.

October 17, 2025
Trust Center - Public
Email
UiPath Security Advisory CVE-2025-55315

Publish Date October 17, 2025

Version 1.0

Summary: UiPath is aware that Microsoft has released a security advisory to provide information about a vulnerability in ASP.NET Core 10.0 , ASP.NET Core 9.0 , ASP.NET Core 8.0, and ASP.NET Core 2.3. The vulnerability is due to inconsistent interpretation of http requests 'http request/response smuggling' in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.

UiPath is currently investigating the impact to our products and systems. We will provide updates as soon as they are available.

CVE-2025-55315 Trust Center updateUpdate November 6, 2025
Patches are now available for all supported .msi packages, and for all affected services deployed through Automation Suite. Download links and release notes are provided below.
Automation Suite

Mitigation measures have been applied for all versions of Document Understanding:

.MSI Packages
Action Center

Insights

Orchestrator (includes Identity)

Test Manager

CVE-2025-55182 & CVE-2025-66478

Vulnerabilities

UiPath has completed our initial investigation of the recent React.js/Next.js vulnerabilities: CVE-2025-55182 and CVE-2025-66478. At this time, no evidence has been found to indicate that UiPath products or UiPath Automation Cloud (including AC Dedicated and AC Public Sector) are affected by this vulnerability. Thank you.

Note: In addition, Cloudflare for AC and Akamai for ACPS already have protections in place.

UiPath Security Advisory Spring4Shell (CVE-2022-22965)

Vulnerabilities

This posting was originally posted to https://www.uipath.com/legal/trust-and-security/security-advisories and migrated to https://trust.uipath.com on November 21, 2025
This advisory is being retained for historical record
UiPath Security Advisory Spring4Shell (CVE-2022-22965)
Publish Date: April 6, 2022

Version: 1.1

The UiPath Security and Product Engineering teams have been performing an exposure analysis of the Spring4Shell vulnerability, categorized as CVE-2022-22965 on the UiPath products.,This post details our progress to date. Note that our assessment of products and services has been completed for the listed CVEs. We plan to update this page as material information becomes available. Our aim is to enable our customers to quickly mitigate risks to their security posture.

  1. The following constitute our findings to date:

The following products contain the vulnerable Spring Framework libraries but have no known risk because exploitation is already mitigated in these products.

UiPath will update these products in a future release.

AI Center
Automation Suite
Cloud Elements
Insights
Test Manager
2. Services in UiPath’s Automation Cloud that contained the vulnerable Spring Framework libraries have already been updated to fully remediate the vulnerability. Please note there was no known risk due to mitigation associated with these services.

  1. The following products, both cloud service and the on-premises versions, do not contain the vulnerable Spring Framework libraries and have no known risk at this time:

Studio (all types), Assistant, Robot (all types including AI Robots, Cloud Robots, etc.). All extensions packaged with Studio (browser extensions, etc.)

All UiPath Activity Packages published to the UiPath Official Feed

Orchestrator
Automation Hub (including Task Capture)
Data Service
Task Mining
Process Mining
Automation Ops
Action Center
Apps
High Availability Add-on (HAA)
This posting was originally posted to https://www.uipath.com/legal/trust-and-security/security-advisories and migrated to https://trust.uipath.com on November 21, 2025
This advisory is being retained for historical record