CVE-2026-25044High· 8.8▾ TwilightBudibase is an open-source low-code platform. Prior to version 3.33.4, the bash automation step executes user-provided commands using execSync without proper sanitization or validation. User input is processed through processStringSync w…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
Budibase is an open-source low-code platform. Prior to version 3.33.4, the bash automation step executes user-provided commands using execSync without proper sanitization or validation. User input is processed through processStringSync which allows template interpolation, potentially allowing arbitrary command execution. This issue has been patched in version 3.33.4.
budibase < 3.33.4Upgrade past the affected range:
budibase 3.33.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-31818Critical· 9.6Budibase is an open-source low-code platform
CVE-2026-25043Medium· 5.3Budibase is an open-source low-code platform
CVE-2026-48128MediumBudibase: SSRF via User-Controlled queryId in Automation Execute Query Step
GHSA-qqf5-x7mj-v43pHigh· 8.4budibase: Database Connector SQL Injections in PostgreSQL, MS SQL, and MySQL
CVE-2018-11138Critical· 9.8The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.
CVE-2020-3167High· 7.8A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS)