CVE-2026-35214High· 8.7▾ TwilightBudibase is an open-source low-code platform. Prior to version 3.33.4, the plugin file upload endpoint (POST /api/plugin/upload) passes the user-supplied filename directly to createTempFolder() without sanitizing path traversal sequences…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 47.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.7%
Budibase is an open-source low-code platform. Prior to version 3.33.4, the plugin file upload endpoint (POST /api/plugin/upload) passes the user-supplied filename directly to createTempFolder() without sanitizing path traversal sequences. An attacker with Global Builder privileges can craft a multipart upload with a filename containing ../ to delete arbitrary directories via rmSync and write arbitrary files via tarball extraction to any filesystem path the Node.js process can access. This issue has been patched in version 3.33.4.
budibase < 3.33.4Upgrade past the affected range:
budibase 3.33.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-35216Critical· 9.0Budibase is an open-source low-code platform
CVE-2026-31818Critical· 9.6Budibase is an open-source low-code platform
CVE-2026-103757High· 7.7Budibase through 3.41.0 contains a server-side request forgery vulnerability in AI table generation because the uploadUrl function in packages/server/src/utilities/fileUtils.ts uses raw node-fetch instead of fetchWithBlacklist
CVE-2026-100682High· 8.8Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon upload endpoint that extracts user-supplied ZIP archives without proper symlink validation
CVE-2026-25044High· 8.8Budibase is an open-source low-code platform
CVE-2026-25043Medium· 5.3Budibase is an open-source low-code platform