Budibase has 50 CVEs on record. Disclosure cadence is accelerating: 31 in the last 90 days against 16 in the 90 before. The busiest recent month was July 2026 with 19. The median CVSS is 7.7 (high), with 7 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-918 (12) and CWE-200 (6). Most affected products: @budibase/server (33), server (9), budibase (6).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.7
- Publish → KEV
- —
- Last 90 days
- 31 prev 16
Weakness classes
Products
- @budibase/server 33
- server 9
- budibase 6
- @budibase/backend-core 2
Worst active — by depth score
CVE-2026-54350Critical· 10.0Budibase has nonymous NoSQL operator injection via published-app query templates67CVE-2026-100682High· 8.8Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon upload endpoint that extracts user-supplied ZIP archives without proper symlink validation61CVE-2026-100686High· 8.1Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endpoint, allowing builders to assign application roles across workspace boundaries57CVE-2026-100684High· 8.1Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server57CVE-2026-100680High· 8.1Budibase versions before 3.45.0 fail to disable external JSON reference resolution in the OpenAPI/Swagger import validator, allowing authenticated builders to read arbitrary local files57
Budibase vulnerabilities
CVEs affecting Budibase, newest first. Open any entry for full detail, references, and exploit status.
50 CVEsRSS
GHSA-2xgg-r2wc-c5r2High· 7.6Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector
Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector
CVE-2026-54350Critical· 10.0PoCBudibase has nonymous NoSQL operator injection via published-app query templates
Budibase has nonymous NoSQL operator injection via published-app query templates
CVE-2026-48153High· 8.5Budibase: SSRF via OAuth2 token endpoint URL reaches internal hosts and cloud metadata
Budibase: SSRF via OAuth2 token endpoint URL reaches internal hosts and cloud metadata
CVE-2026-50132High· 7.3Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF
Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF
CVE-2026-50136High· 7.4Budibase: Unauthenticated S3 signed upload URL generation allows arbitrary writes with stored datasource credentials
Budibase: Unauthenticated S3 signed upload URL generation allows arbitrary writes with stored datasource credentials
CVE-2026-50137HighBudibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentials
Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentials
CVE-2026-54351High· 8.2Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Override
Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Override
CVE-2026-54352Critical· 9.6Budibase has arbitrary file read by workspace-builder via PWA-zip symlink upload
Budibase has arbitrary file read by workspace-builder via PWA-zip symlink upload
CVE-2026-54353High· 8.5@budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation
@budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation
GHSA-qqf5-x7mj-v43pHigh· 8.4budibase: Database Connector SQL Injections in PostgreSQL, MS SQL, and MySQL
budibase: Database Connector SQL Injections in PostgreSQL, MS SQL, and MySQL
CVE-2026-48128MediumBudibase: SSRF via User-Controlled queryId in Automation Execute Query Step
Budibase: SSRF via User-Controlled queryId in Automation Execute Query Step
CVE-2026-48146High· 7.7Budibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist Protection
Budibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist Protection
CVE-2026-48147Medium· 6.5Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Worker
Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Worker
CVE-2026-48148MediumBudibase: Unvalidated VectorDB Host Parameter Enables SSRF
Budibase: Unvalidated VectorDB Host Parameter Enables SSRF
CVE-2026-48150Critical· 9.0Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign
Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign
CVE-2026-48151High· 7.5Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schema
Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schema
CVE-2026-48152High· 8.1Budibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasource base URL
Budibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasource base URL
CVE-2026-31818Critical· 9.6Budibase is an open-source low-code platform
Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST datasource connector. The platform's SSRF protection mechanism (IP blacklist) is rendered…
CVE-2026-25044High· 8.8Budibase is an open-source low-code platform
Budibase is an open-source low-code platform. Prior to version 3.33.4, the bash automation step executes user-provided commands using execSync without proper sanitization or validation. User input is processed through processStringSync w…
CVE-2026-25043Medium· 5.3Budibase is an open-source low-code platform
Budibase is an open-source low-code platform. Prior to version 3.23.25, a business logic vulnerability exists in Budibase’s password reset functionality due to the absence of rate limiting, CAPTCHA, or abuse prevention mechanisms on the …