CVE-2026-35216Critical· 9.0▾ MidnightBudibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) on the Budibase server by triggering an automation that contains a Bash step via the public webhoo…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 49.5 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.2%
Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) on the Budibase server by triggering an automation that contains a Bash step via the public webhook endpoint. No authentication is required to trigger the exploit. The process executes as root inside the container. This issue has been patched in version 3.33.4.
budibase < 3.33.4Upgrade past the affected range:
budibase 3.33.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-35214High· 8.7Budibase is an open-source low-code platform
CVE-2026-31818Critical· 9.6Budibase is an open-source low-code platform
CVE-2026-25044High· 8.8Budibase is an open-source low-code platform
CVE-2026-103757High· 7.7Budibase through 3.41.0 contains a server-side request forgery vulnerability in AI table generation because the uploadUrl function in packages/server/src/utilities/fileUtils.ts uses raw node-fetch instead of fetchWithBlacklist
CVE-2026-25043Medium· 5.3Budibase is an open-source low-code platform
CVE-2026-48128MediumBudibase: SSRF via User-Controlled queryId in Automation Execute Query Step