Budibase
Budibase: vulnerabilidades y CVE
Budibase tiene 86 vulnerabilidades publicadas, 84 de ellas en los últimos 12 meses. 18 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE86
Últimos 12 meses84
Críticas18
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-103757 | Alta (8.3) | 0.26% | — | 1 oct 2026 | Budibase through 3.41.0 contains a server-side request forgery vulnerability in AI table generation because the uploadUrl function in packages/server/src/utilities/fileUtils.ts uses raw node-fetch instead of… |
| CVE-2026-100688 | Alta (7.1) | 0.26% | — | 26 sept 2026 | Budibase server before 3.45.0 contains a cross-tenant information disclosure vulnerability in the GET /api/applications/:appId/appPackage endpoint that allows authenticated users to read another tenant's application… |
| CVE-2026-100686 | Alta (8.6) | 0.21% | — | 26 sept 2026 | Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endpoint, allowing builders to assign application roles across workspace boundaries. A builder of a… |
| CVE-2026-100685 | Alta (8.3) | 0.21% | — | 26 sept 2026 | Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowing builders to enumerate chat identity link records across all workspaces in a tenant. Attackers with builder access to… |
| CVE-2026-100684 | Crítica (9.2) | 0.33% | — | 26 sept 2026 | Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server. In sso.authenticate, when no existing user matches the incoming SSO subject, the server looks up… |
| CVE-2026-100683 | Alta (8.9) | 0.21% | — | 26 sept 2026 | Budibase (@budibase/server) before 3.45.0 builds MySQL and MSSQL column-rename DDL in packages/backend-core/src/sql/sqlTable.ts by interpolating identifiers directly into a raw query string (backtick-quoted for MySQL, a… |
| CVE-2026-100681 | Media (6.3) | 0.25% | — | 26 sept 2026 | Budibase before 3.45.0 contains an unauthenticated server-side request forgery and credential exfiltration vulnerability in the Microsoft Teams webhook endpoint that accepts forged Bot Framework activities with… |
| CVE-2026-100680 | Alta (8.6) | 0.23% | — | 26 sept 2026 | Budibase versions before 3.45.0 fail to disable external JSON reference resolution in the OpenAPI/Swagger import validator, allowing authenticated builders to read arbitrary local files. Attackers with builder access… |
| CVE-2026-82245 | Alta (7.2) | 0.40% | — | 28 ago 2026 | Budibase before 3.41.3 fails to enforce role-based authorization on license management endpoints, allowing any authenticated user to delete license keys or manipulate offline tokens. Attackers with basic user privileges… |
| CVE-2026-82244 | Crítica (9.4) | 0.89% | — | 28 ago 2026 | Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling that allows authenticated admin users to execute arbitrary code by uploading a malicious plugin tarball. The server calls… |
| CVE-2026-82242 | Alta (8.3) | 0.34% | — | 28 ago 2026 | Budibase versions before 3.41.3 contain a missing authorization vulnerability in the POST /api/resources/duplicate endpoint that allows authenticated builders to inject tables, automations, queries, and screens into any… |
| CVE-2026-82241 | Alta (7.1) | 0.30% | — | 28 ago 2026 | Budibase backend-core (@budibase/backend-core, as used by @budibase/server) omits the shared address space range 100.64.0.0/10 from its default SSRF blacklist (DEFAULT_BLACKLIST) used by REST datasource query previews.… |
| CVE-2026-82240 | Alta (8.6) | 0.36% | — | 28 ago 2026 | Budibase before 3.41.3 fails to validate app-scoped builder role assignments in the public user create and update endpoints, allowing an authenticated app-scoped builder to grant builder access to unrelated apps.… |
| CVE-2026-82239 | Alta (8.6) | 0.39% | — | 28 ago 2026 | Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/query endpoint, allowing low-privilege BASIC users to read, create, update, or delete rows in any table regardless of… |
| CVE-2026-73410 | Alta (8.5) | 0.28% | — | 17 ago 2026 | Budibase is an open-source low-code platform. Prior to 3.40.0, packages/backend-core/src/utils/outboundFetch.ts pinned a validated address through a Node agent, but the REST integration used getDispatcher from… |
| CVE-2026-64657 | Alta (8.4) | 0.45% | — | 17 ago 2026 | Budibase is an open-source low-code platform. Prior to 3.39.19, the PostgreSQL datasource connector in packages/server/src/integrations/postgres.ts interpolates the user-controlled schema configuration field into a SET… |
| CVE-2026-54356 | Alta (7.1) | 0.35% | — | 17 ago 2026 | Budibase is an open-source low-code platform. Prior to 3.41.3, POST /api/attachments/:datasourceId/url in packages/server/src/api/routes/static.ts and packages/server/src/api/controllers/static/index.ts allows an… |
| CVE-2026-35219 | Alta (7.1) | 0.46% | — | 17 ago 2026 | Budibase is an open-source low-code platform. Prior to 3.41.3, automation steps in packages/server/src/automations/steps/outgoingWebhook.ts, packages/server/src/automations/steps/zapier.ts,… |
| CVE-2026-72859 | Alta (8.3) | 0.31% | — | 14 ago 2026 | Budibase versions 3.39.4 before 3.40.0 contain an authorization regression in the S3 attachment upload endpoint that allows BASIC users to obtain S3 PutObject presigned URLs by sending POST requests to the attachments… |
| CVE-2026-73408 | Alta (7.6) | 0.45% | — | 13 ago 2026 | Budibase is an open-source low-code platform. Prior to 3.39.18, packages/server/src/integrations/mysql.ts enabled multipleStatements and inserted an unescaped tableName into a DESCRIBE statement. An attacker able to… |
| CVE-2026-73305 | Alta (8.8) | 0.52% | — | 13 ago 2026 | Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRoleUpdate without checking appBuilder.appId or role.appId in… |
| CVE-2026-73304 | Media (4.9) | 0.48% | — | 13 ago 2026 | Budibase is an open-source low-code platform. Prior to 3.39.25, GET /api/users/metadata and GET /api/users/metadata/:id returned user objects processed by packages/server/src/utilities/global.ts without removing… |
| CVE-2026-73302 | Crítica (9) | 0.43% | — | 13 ago 2026 | Budibase is an open-source low-code platform. Prior to 3.39.30, the OIDC flow in packages/backend-core/src/middleware/passport/sso/oidc.ts resolved an email without getEmailVerified or an email_verified requirement, and… |
| CVE-2026-72857 | Alta (8.3) | 0.35% | — | 13 ago 2026 | Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowing authenticated users to read MongoDB connection strings and Firebase private keys in plaintext. Attackers with table… |
| CVE-2026-72856 | Alta (8.6) | 0.47% | — | 13 ago 2026 | Budibase versions before 3.40.0 contain an authorization/authentication bypass in the PUT /api/global/users/tenant/owner (changeTenantOwnerEmail) endpoint. On self-hosted instances (SELF_HOSTED or DISABLE_ACCOUNT_PORTAL… |
| CVE-2026-72855 | Alta (8.4) | 0.38% | — | 13 ago 2026 | Budibase before 3.40.0 contains server-side request forgery vulnerabilities in OpenAPI query import and REST query execution that allow authenticated builder-level users to bypass DNS pinning protections through DNS… |
| CVE-2026-72853 | Alta (8.8) | 0.34% | — | 13 ago 2026 | Budibase before 3.40.0 contains a SQL injection vulnerability in the Oracle datasource connector's post-write row lookup that fails to escape table names in identifiers. Attackers with write permission on a table with a… |
| CVE-2026-72851 | Crítica (9) | 0.42% | — | 13 ago 2026 | Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers can POST attacker-controlled JSON to the webhook trigger endpoint to… |
| CVE-2026-72850 | Crítica (9.4) | 0.60% | — | 13 ago 2026 | Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are preserved during export. Attackers can craft filenames containing ..… |
| CVE-2026-72849 | Alta (8.7) | 0.16% | — | 13 ago 2026 | Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff endpoint that allows attackers to bind an external chat identity to a victim's account. Attackers can craft a phishing… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.