VulnSea

Budibase has 50 CVEs on record. Disclosure cadence is accelerating: 31 in the last 90 days against 16 in the 90 before. The busiest recent month was July 2026 with 19. The median CVSS is 7.7 (high), with 7 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-918 (12) and CWE-200 (6). Most affected products: @budibase/server (33), server (9), budibase (6).

CVEs per month

Last 12 months, by publish date

111201020304050607080910
Exploited share
0% vs 1% corpus
Median CVSS
7.7
Publish → KEV
—
Last 90 days
31 prev 16

Products

  • @budibase/server 33
  • server 9
  • budibase 6
  • @budibase/backend-core 2
50
Total CVEs
7
Critical
0
CISA KEV
0
Exploited

Budibase vulnerabilities

CVEs affecting Budibase, newest first. Open any entry for full detail, references, and exploit status.

50 CVEsRSS

CVE-2026-103757High· 7.7PoC
today

Budibase through 3.41.0 contains a server-side request forgery vulnerability in AI table generation because the uploadUrl function in packages/server/src/utilities/fileUtils.ts uses raw node-fetch instead of fetchWithBlacklist

Budibase through 3.41.0 contains a server-side request forgery vulnerability in AI table generation because the uploadUrl function in packages/server/src/utilities/fileUtils.ts uses raw node-fetch instead of fetchWithBlacklist. Authentic…

▾ MidnightBudibase · budibasevia NVD
CVE-2026-100682High· 8.8PoC
5d ago

Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon upload endpoint that extracts user-supplied ZIP archives without proper symlink validation

Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon upload endpoint that extracts user-supplied ZIP archives without proper symlink validation. Attackers with BUILDER role can craft a malicious ZI…

▾ Midnightbudibase · serverEPSS 0.57%via NVD
CVE-2026-100681Medium· 5.4PoC
5d ago

Budibase before 3.45.0 contains an unauthenticated server-side request forgery and credential exfiltration vulnerability in the Microsoft Teams webhook endpoint that accepts forged Bot Framework activities with arbitrary serviceUrl value…

Budibase before 3.45.0 contains an unauthenticated server-side request forgery and credential exfiltration vulnerability in the Microsoft Teams webhook endpoint that accepts forged Bot Framework activities with arbitrary serviceUrl value…

▾ Twilightbudibase · serverEPSS 0.25%via NVD
CVE-2026-100686High· 8.1PoC
5d ago

Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endpoint, allowing builders to assign application roles across workspace boundaries

Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endpoint, allowing builders to assign application roles across workspace boundaries. A builder of a single workspace can …

▾ Midnightbudibase · serverEPSS 0.21%via NVD
CVE-2026-100685High· 7.7PoC
5d ago

Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowing builders to enumerate chat identity link records across all workspaces in a tenant

Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowing builders to enumerate chat identity link records across all workspaces in a tenant. Attackers with builder access to a single workspac…

▾ Midnightbudibase · serverEPSS 0.21%via NVD
CVE-2026-100680High· 8.1PoC
5d ago

Budibase versions before 3.45.0 fail to disable external JSON reference resolution in the OpenAPI/Swagger import validator, allowing authenticated builders to read arbitrary local files

Budibase versions before 3.45.0 fail to disable external JSON reference resolution in the OpenAPI/Swagger import validator, allowing authenticated builders to read arbitrary local files. Attackers with builder access can embed file:// re…

▾ Midnightbudibase · serverEPSS 0.23%via NVD
CVE-2026-100687Medium· 5.5
5d ago

Budibase Server before 3.45.0 fails to redact plaintext datasource credentials before broadcasting external table updates to the Builder collaboration websocket room

Budibase Server before 3.45.0 fails to redact plaintext datasource credentials before broadcasting external table updates to the Builder collaboration websocket room. Attackers with Builder access can intercept unredacted datasource obje…

▾ Sunlitbudibase · serverEPSS 0.26%via NVD
CVE-2026-100683High· 8.0PoC
5d ago

Budibase (@budibase/server) before 3.45.0 builds MySQL and MSSQL column-rename DDL in packages/backend-core/src/sql/sqlTable.ts by interpolating identifiers directly into a raw query string (backtick-quoted for MySQL, a single-quoted sp_…

Budibase (@budibase/server) before 3.45.0 builds MySQL and MSSQL column-rename DDL in packages/backend-core/src/sql/sqlTable.ts by interpolating identifiers directly into a raw query string (backtick-quoted for MySQL, a single-quoted sp_…

▾ Midnightbudibase · serverEPSS 0.21%via NVD
CVE-2026-100684High· 8.1PoC
5d ago

Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server

Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server. In sso.authenticate, when no existing user matches the incoming SSO subject, the server looks up pending user invites…

▾ Midnightbudibase · serverEPSS 0.33%via NVD
CVE-2026-100688Medium· 6.5PoC
5d ago

Budibase server before 3.45.0 contains a cross-tenant information disclosure vulnerability in the GET /api/applications/:appId/appPackage endpoint that allows authenticated users to read another tenant's application metadata and source c…

Budibase server before 3.45.0 contains a cross-tenant information disclosure vulnerability in the GET /api/applications/:appId/appPackage endpoint that allows authenticated users to read another tenant's application metadata and source c…

▾ Twilightbudibase · serverEPSS 0.26%via NVD
CVE-2026-54356High· 7.1PoC
1mo ago

Budibase is an open-source low-code platform

Budibase is an open-source low-code platform. Prior to 3.41.3, POST /api/attachments/:datasourceId/url in packages/server/src/api/routes/static.ts and packages/server/src/api/controllers/static/index.ts allows an authenticated published-…

▾ Midnightbudibase · @budibase/serverEPSS 0.35%via NVD
CVE-2026-35219High
1mo ago

Budibase is an open-source low-code platform

Budibase is an open-source low-code platform. Prior to 3.41.3, automation steps in packages/server/src/automations/steps/outgoingWebhook.ts, packages/server/src/automations/steps/zapier.ts, packages/server/src/automations/steps/n8n.ts, p…

▾ Twilightbudibase · @budibase/serverEPSS 0.46%via NVD
GHSA-pvcr-8mvp-w8qrHigh· 7.7
2mo ago

Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)

Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-cr7p-cr3q-h5cmMedium· 5.3
2mo ago

Budibase: Account Enumeration via Login Lockout Response Differential

Budibase: Account Enumeration via Login Lockout Response Differential

▾ Sunlitbudibase · @budibase/servervia GHSA
GHSA-pmpg-2mxq-6xwrHigh· 7.1
2mo ago

Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete

Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-v42f-v8xc-j435High· 8.5
2mo ago

Budibase: SSRF via DNS rebinding in the REST datasource integration

Budibase: SSRF via DNS rebinding in the REST datasource integration

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-hfhx-w8p8-4hc7Medium
2mo ago

Budibase: SSRF via bare fetch() in uploadUrl during AI table generation

Budibase: SSRF via bare fetch() in uploadUrl during AI table generation

▾ Sunlitbudibase · @budibase/servervia GHSA
GHSA-j9fc-w3mr-x6mvHigh· 8.8
2mo ago

Budibase: Privilege escalation via public role assignment API missing app-level authorization

Budibase: Privilege escalation via public role assignment API missing app-level authorization

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-4qcj-m5wp-jmf4Medium· 4.3
2mo ago

Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings

Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings

▾ Sunlitbudibase · @budibase/servervia GHSA
GHSA-fcrw-f7gg-6g9fMedium· 4.9
2mo ago

Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users

Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users

▾ Sunlitbudibase · @budibase/servervia GHSA
GHSA-c8vc-7pv3-g98pHigh
2mo ago

Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)

Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-q6x4-v3qx-85qwCritical· 9.6
2mo ago

Budibase: SQL Injection via `multipleStatements: true`

Budibase: SQL Injection via `multipleStatements: true`

▾ Midnightbudibase · @budibase/servervia GHSA
GHSA-ppr4-5f46-j9c6High
2mo ago

Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile

Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-xcx6-4f2g-hhgxHigh· 7.7
2mo ago

Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLs

Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLs

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-xg5g-26x8-cvf4High· 8.5
2mo ago

Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution

Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-hp6v-6jw7-gv2fCritical
2mo ago

Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified

Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified

▾ Midnightbudibase · @budibase/servervia GHSA
GHSA-mqhr-6j6h-74p5Critical
2mo ago

Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak

Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak

▾ Midnightbudibase · @budibase/servervia GHSA
GHSA-hr66-5mqr-8mpxHigh· 7.5
2mo ago

Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint

Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-gh4h-34gr-87r7Medium· 5.7
2mo ago

Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders

Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders

▾ Sunlitbudibase · @budibase/servervia GHSA
GHSA-qw6m-8fw2-2v64High· 8.3
2mo ago

Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution

Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution

▾ Twilightbudibase · @budibase/servervia GHSA
Budibase vulnerabilities (CVEs) · VulnSea