@budibase/server vulnerabilities
CVEs whose affected-version data names the @budibase/server package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
33 CVEsRSS
CVE-2026-54356High· 7.1PoCBudibase is an open-source low-code platform
Budibase is an open-source low-code platform. Prior to 3.41.3, POST /api/attachments/:datasourceId/url in packages/server/src/api/routes/static.ts and packages/server/src/api/controllers/static/index.ts allows an authenticated published-…
CVE-2026-35219HighBudibase is an open-source low-code platform
Budibase is an open-source low-code platform. Prior to 3.41.3, automation steps in packages/server/src/automations/steps/outgoingWebhook.ts, packages/server/src/automations/steps/zapier.ts, packages/server/src/automations/steps/n8n.ts, p…
GHSA-pvcr-8mvp-w8qrHigh· 7.7Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)
Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)
GHSA-cr7p-cr3q-h5cmMedium· 5.3Budibase: Account Enumeration via Login Lockout Response Differential
Budibase: Account Enumeration via Login Lockout Response Differential
GHSA-pmpg-2mxq-6xwrHigh· 7.1Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete
Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete
GHSA-v42f-v8xc-j435High· 8.5Budibase: SSRF via DNS rebinding in the REST datasource integration
Budibase: SSRF via DNS rebinding in the REST datasource integration
GHSA-hfhx-w8p8-4hc7MediumBudibase: SSRF via bare fetch() in uploadUrl during AI table generation
Budibase: SSRF via bare fetch() in uploadUrl during AI table generation
GHSA-j9fc-w3mr-x6mvHigh· 8.8Budibase: Privilege escalation via public role assignment API missing app-level authorization
Budibase: Privilege escalation via public role assignment API missing app-level authorization
GHSA-4qcj-m5wp-jmf4Medium· 4.3Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings
Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings
GHSA-fcrw-f7gg-6g9fMedium· 4.9Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users
Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users
GHSA-c8vc-7pv3-g98pHighBudibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)
Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)
GHSA-q6x4-v3qx-85qwCritical· 9.6Budibase: SQL Injection via `multipleStatements: true`
Budibase: SQL Injection via `multipleStatements: true`
GHSA-ppr4-5f46-j9c6HighBudibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile
Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile
GHSA-xcx6-4f2g-hhgxHigh· 7.7Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLs
Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLs
GHSA-xg5g-26x8-cvf4High· 8.5Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution
Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution
GHSA-hp6v-6jw7-gv2fCriticalBudibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified
Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified
GHSA-mqhr-6j6h-74p5CriticalBudibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak
Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak
GHSA-hr66-5mqr-8mpxHigh· 7.5Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint
Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint
GHSA-gh4h-34gr-87r7Medium· 5.7Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders
Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders
GHSA-qw6m-8fw2-2v64High· 8.3Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution
Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution
GHSA-2xgg-r2wc-c5r2High· 7.6Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector
Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector
CVE-2026-54350Critical· 10.0PoCBudibase has nonymous NoSQL operator injection via published-app query templates
Budibase has nonymous NoSQL operator injection via published-app query templates
CVE-2026-48153High· 8.5Budibase: SSRF via OAuth2 token endpoint URL reaches internal hosts and cloud metadata
Budibase: SSRF via OAuth2 token endpoint URL reaches internal hosts and cloud metadata
CVE-2026-50132High· 7.3Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF
Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF
CVE-2026-50136High· 7.4Budibase: Unauthenticated S3 signed upload URL generation allows arbitrary writes with stored datasource credentials
Budibase: Unauthenticated S3 signed upload URL generation allows arbitrary writes with stored datasource credentials
CVE-2026-50137HighBudibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentials
Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentials
CVE-2026-54351High· 8.2Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Override
Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Override
CVE-2026-54352Critical· 9.6Budibase has arbitrary file read by workspace-builder via PWA-zip symlink upload
Budibase has arbitrary file read by workspace-builder via PWA-zip symlink upload
CVE-2026-48146High· 7.7Budibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist Protection
Budibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist Protection
CVE-2026-48148MediumBudibase: Unvalidated VectorDB Host Parameter Enables SSRF
Budibase: Unvalidated VectorDB Host Parameter Enables SSRF