GHSA-2xgg-r2wc-c5r2High· 7.6▾ TwilightBudibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
This is a related but independently fixable vulnerability to GHSA-qqf5-x7mj-v43p (PostgreSQL SQL injection), reported in the same original disclosure and split per GitHub CNA guidance (rule 4.2.11) since it affects a separate integration, has a distinct attack precondition, and requires a separate patch.
The MySQL integration enables multipleStatements: true on the connection,
permitting semicolon-separated multi-statement execution. During table
introspection, table names retrieved from INFORMATION_SCHEMA.TABLES are
interpolated into a DESCRIBE query wrapped in backticks, but embedded
backticks in the table name are never escaped — allowing a malicious table
name to break out and inject a second, attacker-controlled statement.
Vulnerable Code:
File: packages/server/src/integrations/mysql.ts, lines 172, 305
this.config = { ...config, multipleStatements: true, ... } // line 172
...
{ sql: `DESCRIBE \`${tableName}\`;` } // line 305 — backtick NOT escaped
Because multipleStatements is enabled, any statement appended after the
backtick break-out executes as a second query in the same round trip.
foo`; DROP TABLE users; --INFORMATION_SCHEMA.TABLES
and interpolates it into the DESCRIBE query.multipleStatements: true)
executes as a second statement.Arbitrary SQL execution triggered during routine schema discovery. Unlike the PostgreSQL and MS SQL Server findings, this does not require the attacker to control the Budibase datasource configuration directly — only the ability to create a maliciously named table in the underlying database beforehand, with an administrator's normal use of the introspection feature serving as the trigger.
@budibase/server <= 3.38.1Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
GHSA-pmpg-2mxq-6xwrHigh· 7.1Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete
GHSA-q6x4-v3qx-85qwCritical· 9.6Budibase: SQL Injection via `multipleStatements: true`
CVE-2026-54350Critical· 10.0Budibase has nonymous NoSQL operator injection via published-app query templates
CVE-2026-54356High· 7.1Budibase is an open-source low-code platform
CVE-2026-35219HighBudibase is an open-source low-code platform
GHSA-pvcr-8mvp-w8qrHigh· 7.7Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)