@budibase/server vulnerabilities
CVEs whose affected-version data names the @budibase/server package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
33 CVEsRSS
CVE-2026-48150Critical· 9.0Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign
Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign
▾ Midnightbudibase · @budibase/serverEPSS 0.29%via GHSA
CVE-2026-48151High· 7.5Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schema
Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schema
▾ Twilightbudibase · @budibase/serverEPSS 0.22%via GHSA
CVE-2026-48152High· 8.1Budibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasource base URL
Budibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasource base URL
▾ Twilightbudibase · @budibase/serverEPSS 0.26%via GHSA