---
id: CVE-2026-82244
title: >-
  Budibase versions before 3.41.3 contain a remote code execution vulnerability
  in plugin handling that allows authenticated admin users to execute arbitrary
  code by uploading a malicious plugin tarball
summary: >-
  Budibase versions before 3.41.3 contain a remote code execution vulnerability
  in plugin handling that allows authenticated admin users to execute arbitrary
  code by uploading a malicious plugin tarball. The server calls eval() on
  plugin J…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-94
vendor: budibase
product: server
affected:
  - server < 3.41.3
published: '2026-08-28'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:47.623'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82244'
references:
  - url: >-
      https://github.com/Budibase/budibase/security/advisories/GHSA-gwr2-pgg3-p7xp
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/budibase-before-3.41.3-remote-code-execution-via-plugin-eval
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-08-28T15:40:01.032491Z'
epss: 0.00886
epssPercentile: 0.58004
ingestedAt: '2026-10-08T16:52:14.733Z'
---

## Overview

Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling that allows authenticated admin users to execute arbitrary code by uploading a malicious plugin tarball. The server calls eval() on plugin JavaScript files without sandboxing in the main Node.js process, enabling attackers to exfiltrate environment variables and credentials with root privileges in default deployments.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
