ToolJet Security Scanner
Building internal tools with ToolJet? Make sure your data sources, queries, and user permissions are locked down before deployment.
Enter your deployed app's URL. Review the findings, take the suggested fixes to your coding tool, and retest after making changes.
First scan free: issue counts and one finding revealed in detail. No card required.
Top 4 Security Issues in ToolJet Apps
Unparameterized AI Queries
ToolJet 3.0's AI Query Builder generates SQL from natural language. These queries may not use parameterized inputs, creating injection vectors.
Exposed Data Source Credentials
Database passwords and API keys may be accessible to all workspace members or exposed through misconfigurations.
Admin Panel Without Auth
Self-hosted ToolJet instances may expose the admin interface without proper authentication or IP restrictions.
Overly Permissive Query Access
Users may be able to execute any query against connected data sources, not just the queries their role requires.
Where Security Breaks in ToolJet Apps
Built on Postgres, ToolJet applications share a recognizable fingerprint, which means attackers and automated scanners find them the same way every time. Based on real vulnerability patterns in ToolJet deployments, the breakdown is 0 critical-impact issues, 3 high-impact, and 1 medium-or-lower.
Unparameterized AI Queries
ToolJet 3.0's AI Query Builder generates SQL from natural language. These queries may not use parameterized inputs, creating injection vectors.
Fix: Use parameterized queries, sanitize all user input, and render dynamic content with framework escaping (React JSX, not dangerouslySetInnerHTML).
Exposed Data Source Credentials
Database passwords and API keys may be accessible to all workspace members or exposed through misconfigurations.
Fix: Move all secrets server-side (environment variables, serverless functions). Rotate any keys previously in frontend code. Audit bundles for leftover credentials before each deploy.
Admin Panel Without Auth
Self-hosted ToolJet instances may expose the admin interface without proper authentication or IP restrictions.
Fix: Enforce email verification, minimum password requirements, and rate limiting on auth endpoints. Test auth flows as unauthenticated and cross-user to verify access controls.
Overly Permissive Query Access
Users may be able to execute any query against connected data sources, not just the queries their role requires.
Fix: Scan your deployed application with a security tool that understands this stack. Address the specific findings — generic best practices don't catch platform-specific misconfigurations.
What We Check
Credential Exposure
Scans for database connection strings and API keys accessible in frontend code.
Query Security
Analyzes queries for SQL injection risks from AI-generated code.
Access Controls
Tests user permission groups and query-level access restrictions.
Deployment Config
Checks for exposed admin panels, default credentials, and missing headers.
What You'll Get
Why ToolJet Apps Need Security Scanning
ToolJet is an open-source low-code platform for building internal tools. Its AI Query Builder makes it faster to create data-driven apps, but internal tools often have direct access to production databases.
The biggest risk is that internal tools are treated as trusted by default. A single misconfigured permission can give attackers access to your production database. vas scans for these issues.
How ToolJet Security Scanning Works
Submit Your URL
Enter your ToolJet application URL. Our scanner automatically detects your tech stack and configures the appropriate security checks for ToolJet.
Automated Analysis
We check the reachable app for exposed secrets, browser protections, authentication issues and database access problems. A standard scan typically takes a few minutes; blocked requests or incomplete coverage are reported.
Get Actionable Results
Receive a detailed report with prioritized vulnerabilities, severity ratings, and step-by-step remediation guidance with code examples specific to ToolJet.
Common Questions About ToolJet Security
What does a VAS scan of a ToolJet app check?
VAS checks the deployed pages, scripts and endpoints it can reach for issues including credential exposure, query security, access controls, deployment config. The report records findings and coverage limits; it does not certify the whole app as secure.
What will I receive in the report?
Findings include severity, supporting evidence and remediation guidance. Your first scan is free, with issue counts and one finding revealed in detail. Paid report access unlocks every finding. Use Export for AI to bring available findings into your coding tool, review the proposed changes and retest.
Can a scan verify every permission and private workflow?
No. Coverage depends on reachable pages, discovered endpoints and enabled checks. Configure a test login for supported authenticated checks. Review source code and business-specific permissions separately. Zero findings does not prove an app is secure.
Does VAS change my code or database policies?
VAS provides recommendations, not automatic fixes. Adapt any suggested policy or code change to your data model, test that permitted users still have access and that other users do not, then rescan. Read checks alone cannot confirm insert, update or delete permissions.
What should I know before scanning a production app?
Only scan apps you own or have permission to test. Scan requests can trigger firewall rules, logs and rate limits. Review enabled checks, and use staging or dedicated test accounts for sensitive workflows. Active tests, where enabled, need separate care because they can make changes.
Remediation Playbook for ToolJet
Priority-ordered fixes for the specific findings we see in ToolJet apps. Critical items close data-exposure gaps; high items prevent compromise; medium items reduce attack surface. Applies to apps using Postgres, the dominant ToolJet stack.
1. Unparameterized AI Queries
Why it matters: ToolJet 3.0's AI Query Builder generates SQL from natural language. These queries may not use parameterized inputs, creating injection vectors.
How to close it: Use parameterized queries, sanitize all user input, and render dynamic content with framework escaping (React JSX, not dangerouslySetInnerHTML).
2. Exposed Data Source Credentials
Why it matters: Database passwords and API keys may be accessible to all workspace members or exposed through misconfigurations.
How to close it: Move all secrets server-side (environment variables, serverless functions). Rotate any keys previously in frontend code. Audit bundles for leftover credentials before each deploy.
3. Admin Panel Without Auth
Why it matters: Self-hosted ToolJet instances may expose the admin interface without proper authentication or IP restrictions.
How to close it: Enforce email verification, minimum password requirements, and rate limiting on auth endpoints. Test auth flows as unauthenticated and cross-user to verify access controls.
4. Overly Permissive Query Access
Why it matters: Users may be able to execute any query against connected data sources, not just the queries their role requires.
How to close it: Scan your deployed application with a security tool that understands this stack. Address the specific findings — generic best practices don't catch platform-specific misconfigurations.
Verify the fixes stuck
Rescan after deploying a fix to check whether the original finding still appears. Compare the evidence and coverage with the previous report. For permissions and private workflows, also repeat the relevant tests with authorized and unauthorized test users.
Check your ToolJet app
Find observable security issues in your deployed app, review the evidence and take the next steps with your coding tool.
Start with a free scan. See issue counts and one finding in detail, then decide whether you need full report access.
More on ToolJet Security
Every angle of ToolJet security, from the specific findings we detect to step-by-step fixes.
ToolJet Security Risks
Specific risks we find in ToolJet apps, with real-world examples.
ToolJet Security Issues
Issues grouped by severity with detection and fix steps.
ToolJet Security Checklist
Pre-launch checklist covering every finding class for ToolJet.
How to Secure ToolJet Apps
Step-by-step hardening guide for ToolJet deployments.