These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
Budibase server before 3.45.0 contains a cross-tenant information disclosure vulnerability in the GET /api/applications/:appId/appPackage endpoint. This allows authenticated users to read another tenant's application metadata and source code by supplying a victim tenant's app id. The vulnerability impacts Budibase server administrators and users who rely on the affected endpoint for application metadata a [truncated]
Budibase Server before 3.45.0 Credential Exposure via External Table Broadcast AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-26T13:23:47.369Z and has not been modified since then. Affected product deployments should be reviewed for exposure, and administrators should prioritize updating to version 3.45.0 or later to prevent credential exposure. [truncated]
Budibase versions before 3.45.0 are vulnerable to cross-workspace privilege escalation via the POST /api/global/groups/:groupId/apps endpoint. This issue allows builders to assign application roles across workspace boundaries, potentially leading to unauthorized access and privilege escalation. The vulnerability has a high CVSS score of 8.6, indicating a significant risk to affected systems. Budibase serv [truncated]
Budibase server versions before 3.45.0 improperly scope the GET /api/chat-links endpoint by workspace. This flaw allows builders with access to a single workspace to enumerate chat identity link records across all workspaces in a tenant. Sensitive data, including user IDs and external chat service identifiers, can be retrieved from workspaces the attacker has no permission to access.
Budibase Server versions 3.41.0 before 3.45.0 contain an authentication bypass vulnerability in the OIDC/SSO login path. An attacker can claim a pending user invite by asserting a victim's invited email address, potentially leading to full tenant compromise. This vulnerability allows an attacker to bypass authentication and gain unauthorized access to the system. The affected product deployments should be [truncated]
Budibase server versions before 3.45.0 are vulnerable to SQL injection attacks via column-rename DDL operations. The vulnerability arises from the direct interpolation of identifiers into raw query strings without proper quoting, allowing an attacker with DDL rights on a connected MySQL or MSSQL datasource to inject malicious SQL. This can lead to arbitrary reads, writes, or destructive operations on the [truncated]
Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon upload endpoint that extracts user-supplied ZIP archives without proper symlink validation. Attackers with BUILDER role can craft a malicious ZIP with leaf symlink entries followed by duplicate file entries to write arbitrary files as root, enabling remote code execution.
Budibase server versions before 3.45.0 contain an unauthenticated server-side request forgery and credential exfiltration vulnerability in the Microsoft Teams webhook endpoint. This vulnerability allows attackers to submit a crafted POST request with an arbitrary serviceUrl value that is persisted and used for all subsequent bot replies. As a result, the server sends live Microsoft OAuth access tokens in [truncated]
Budibase server versions before 3.45.0 are vulnerable to arbitrary local file reads via OpenAPI import. Authenticated builders can exploit this by embedding file:// references in OpenAPI specifications to exfiltrate sensitive files, including environment variables with JWT secrets, API keys, and database credentials. This vulnerability has a high CVSS score of 8.6, indicating a high severity. The CVE reco [truncated]
Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the query import endpoint. This vulnerability allows attackers to submit arbitrary URLs to retrieve responses from internal services, including cloud metadata endpoints and other restricted network resources. The vulnerability can lead to potential unauthorized access to internal services and sensitive data, disrupt crit [truncated]
Budibase server versions before 3.41.3 are vulnerable to unauthorized license management due to a missing authorization check on license management endpoints. This allows any authenticated user to delete license keys or manipulate offline tokens, effectively downgrading deployments and disabling premium features for all users. Budibase server administrators and users with access to license management func [truncated]
Budibase server versions before 3.41.3 contain a remote code execution vulnerability in plugin handling. Authenticated admin users can execute arbitrary code by uploading a malicious plugin tarball. The server calls eval() on plugin JavaScript files without sandboxing in the main Node.js process, enabling attackers to exfiltrate environment variables and credentials with root privileges in default deployments.
Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the datasource verify endpoint that allows builder-level users to supply arbitrary URLs without SSRF validation. This issue requires immediate attention to prevent potential credential leakage. The vulnerability exists in the datasource verify endpoint and allows builder-level users to supply arbitrary URLs without prope [truncated]
CVE-2026-82240 is a high-severity vulnerability in Budibase server versions before 3.41.3. An authenticated app-scoped builder can exploit this issue to escalate privileges and gain unauthorized builder access to other applications in the same tenant via the user update API. This vulnerability allows attackers to submit crafted requests to the user update API with builder.apps fields to escalate privilege [truncated]
Budibase server versions before 3.41.3 are vulnerable to an authorization bypass via the datasources/query endpoint. This allows low-privilege BASIC users to read, create, update, or delete rows in any table, regardless of configured permissions. The vulnerability impacts Budibase deployments with BASIC user roles, enabling unauthorized data access or modification. Defenders should assess exposure and pri [truncated]
Budibase, an open-source low-code platform, had a vulnerability prior to version 3.40.0 that allowed a builder to use DNS rebinding to make the REST integration connect to an internal address after a public address passed validation. This issue is fixed in version 3.40.0. The vulnerability enabled unauthorized access to internal addresses, potentially leading to data breaches. Defenders should assess expo [truncated]
Budibase, an open-source low-code platform, had a vulnerability in its PostgreSQL datasource connector prior to version 3.39.19. An authenticated administrator could execute arbitrary SQL through the simple query protocol by interpolating a user-controlled schema configuration field into a SET search_path statement without escaping embedded double quotes. This issue was fixed in version 3.39.19.
Budibase open-source low-code platform vulnerability allows authenticated users to obtain signed and public URLs backed by stored S3 credentials. Fixed in version 3.41.3. The issue arises from inadequate validation of user-supplied input, enabling attackers to manipulate bucket and key values. This could lead to unauthorized access to sensitive data stored in S3. Users with the BASIC role in published app [truncated]
Budibase, an open-source low-code platform, contains a vulnerability prior to version 3.41.3 that allows an authenticated user to make server-side requests to cloud metadata and internal services. This issue arises from automation steps in various files using node-fetch on user-provided URLs without the BLACKLIST_IPS enforcement used by the REST integration.
Budibase versions 3.39.4 before 3.40.0 contain an authorization regression in the S3 attachment upload endpoint that allows BASIC users to obtain S3 PutObject presigned URLs by sending POST requests to the attachments endpoint. The route was changed from a BUILDER permission check to a TABLE/WRITE check, which BASIC users hold by default. Attackers can specify arbitrary S3 buckets in the request body to g [truncated]
Budibase, an open-source low-code platform, had a vulnerability prior to version 3.39.18. The packages/server/src/integrations/mysql.ts file enabled multipleStatements and inserted an unescaped tableName into a DESCRIBE statement. An attacker who could create a MySQL table with a backtick and stacked statement in its name could potentially execute a second statement when a Budibase administrator ran schem [truncated]
Budibase, an open-source low-code platform, had a vulnerability prior to version 3.39.24 where an app-scoped builder could potentially grant themselves builder access or an arbitrary role in another app, exposing that app's data, datasource configuration, and automations. This issue was fixed in version 3.39.24. The vulnerability allowed an app-scoped builder to potentially grant themselves elevated privi [truncated]
A vulnerability in Budibase, an open-source low-code platform, allowed users with the POWER role to retrieve identity-provider credentials of SSO-authenticated users via GET /api/users/metadata and GET /api/users/metadata/:id. This issue, fixed in version 3.39.25, could enable persistent access to connected services through refresh tokens. The vulnerability was caused by user objects being processed witho [truncated]
CVE-2026-73302 Budibase OIDC flow vulnerability allows account merging and role inheritance. The Budibase OIDC flow vulnerability enables an attacker to merge a fresh provider identity into a victim's Budibase account and inherit their roles. This issue is fixed in version 3.39.30. Defenders should verify Budibase deployments using OIDC for authentication and prioritize upgrading to version 3.39.30 or lat [truncated]
Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowing authenticated users to read MongoDB connection strings and Firebase private keys in plaintext. Attackers with table read permissions can retrieve datasource configurations through the read API to obtain live backend database credentials and service account keys. This vulnerability affects Budibase users w [truncated]
Budibase before 3.40.0 contains a SQL injection vulnerability in the Oracle datasource connector's post-write row lookup. The vulnerability allows attackers with write permission on a table with a double-quote in its name to inject SQL that executes as the datasource's database user, potentially leading to arbitrary data reads or modifications. This issue highlights the importance of proper input validati [truncated]
Budibase before 3.40.0 contains server-side request forgery vulnerabilities in OpenAPI query import and REST query execution that allow authenticated builder-level users to bypass DNS pinning protections through DNS rebinding attacks. Attackers can configure hostnames that resolve to public addresses during validation but resolve to loopback or private addresses during actual connection, allowing access t [truncated]
Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers can POST attacker-controlled JSON to the webhook trigger endpoint to inject SQL payloads that execute with builder-configured database credentials, enabling data exfiltration, modification, and persistence in connected datasources like Snowflake.
Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff endpoint. Attackers can craft a phishing page that auto-submits a POST request with a leaked confirmation token to bind their chat identity to a victim user's account, enabling impersonation within agent operations and inheritance of victim permissions. This vulnerability allows for potential cross-site req [truncated]
Budibase Server before version 3.40.0 contains a NoSQL injection vulnerability in the MongoDB query execution endpoint. User-supplied parameters are interpolated into JSON query templates without proper sanitization of JSON metacharacters, allowing attackers with query write permission to inject JSON structural characters and alter MongoDB queries. This vulnerability can be mitigated by applying the patch [truncated]