---
id: CVE-2026-72850
title: >-
  Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing
  authenticated builders to upload files with traversal sequences that are
  preserved during export
summary: >-
  Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing
  authenticated builders to upload files with traversal sequences that are
  preserved during export. Attackers can craft filenames containing .. segments
  that escape…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-22
vendor: budibase
product: server
affected:
  - server < 3.40.0
published: '2026-08-13'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:36.813'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-72850'
references:
  - url: >-
      https://github.com/Budibase/budibase/security/advisories/GHSA-pxwc-66g3-5f27
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/budibase-before-arbitrary-file-write-via-path-traversal
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Budibase/budibase/security/advisories/GHSA-pxwc-66g3-5f27
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-08-14T16:13:36.513573Z'
epss: 0.00605
epssPercentile: 0.47287
ingestedAt: '2026-10-08T16:52:14.716Z'
---

## Overview

Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are preserved during export. Attackers can craft filenames containing .. segments that escape the temporary directory during workspace export, writing arbitrary content to any path writable by the Budibase process.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
