These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
Budibase before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB datasource integration. User-supplied parameters are enriched with handlebars using noEscaping: true and parsed without operator filtering, allowing attackers to inject MongoDB operators. This could lead to unauthorized data access, modification, or execution of JavaScript via $where operators. Affected organizations should pri [truncated]
Budibase, an open-source low-code platform, had a vulnerability prior to version 3.40.1 where it passed builder-controlled tlsCertificateKeyFile and tlsCAFile values directly to MongoClient on Budibase Cloud. This allowed a builder to submit absolute server paths through /api/datasources/verify and distinguish readable existing files from missing files by comparing the driver error, exposing a filesystem [truncated]
Budibase, an open-source low-code platform, had a critical vulnerability prior to version 3.40.1. The RestIntegration._req function in packages/server/src/integrations/rest.ts improperly handled authentication headers, allowing an unauthenticated attacker to potentially obtain stored bearer, basic, or static-header credentials by supplying a malicious path to a PUBLIC POST /api/v2/queries/:queryId query. [truncated]
Budibase, an open-source low-code platform, had an issue where an unauthenticated caller could query for user information, including email addresses and tenant identifiers, due to the GET /api/global/users/tenant/:id endpoint being listed in PUBLIC_ENDPOINTS. This issue is fixed in version 3.39.32. The vulnerability allowed defenders to verify exposure and apply the patch. Budibase deployments, especially [truncated]
CVE-2026-73308 Budibase Low-Code Platform Vulnerability. Budibase, an open-source low-code platform, had a vulnerability prior to version 3.39.25 that could expose OAuth2 access and refresh tokens of other SSO-authenticated builders. This issue allowed co-builders to potentially receive or poll automation test results and obtain these tokens. The vulnerability was fixed by adding sanitizeAutomationTestRes [truncated]
CVE-2026-73306 Budibase Authentication Enumeration and Temporary Lockout. Budibase, an open-source low-code platform, had an authentication issue allowing user enumeration and temporary account lockout. The failure counter for login attempts was only incremented for existing users, enabling an unauthenticated attacker to compare responses and enumerate valid email addresses. Valid accounts could also be t [truncated]
CVE-2026-73303 Budibase Email Change Vulnerability. Budibase, an open-source low-code platform, had a vulnerability prior to version 3.40.0 that allowed an authenticated attacker to change the email address of a victim user and potentially reset their password. This issue is fixed in version 3.40.0. Defenders should prioritize upgrading and monitoring for suspicious activities. The vulnerability had a hig [truncated]
CVE-2026-73301 Budibase low-code platform vulnerability allows authenticated BASIC role users to enumerate sensitive tenant information, including groups, role mappings, and user memberships. The issue is due to an authentication bypass in the GET /api/global/groups endpoint. This vulnerability has a CVSS score of 4.3 and is classified as MEDIUM severity. The issue is fixed in version 3.39.25. Defenders s [truncated]
Budibase, an open-source low-code platform, had a critical vulnerability prior to version 3.40.0. The MySQL integration component was configured with multipleStatements: true, allowing execution of multiple SQL statements in a single query. This enabled attackers to inject malicious SQL commands through user input fields, potentially leading to complete database compromise. The vulnerability was fixed in [truncated]
CVE-2026-54353 is a Server-Side Request Forgery (SSRF) vulnerability in Budibase, an open-source low-code platform. Authenticated users with automation permissions can bypass Budibase's SSRF blacklist through DNS rebinding. The outbound fetch flow validates a hostname against the blacklist before the request is sent, but the actual socket connection later performs a separate DNS lookup through node-fetch. [truncated]
CVE-2026-54352 is a critical vulnerability in Budibase, an open-source low-code platform. The vulnerability allows a workspace-level builder to read any file the server process can open. This is possible due to a flaw in the `POST /api/pwa/process-zip` endpoint, which accepts a builder-uploaded .zip file, extracts it, and then streams the bytes of the extracted files into MinIO. The issue arises because e [truncated]
CVE-2026-54351 is a high-severity vulnerability in Budibase, an open-source low-code platform. The issue arises from the webhook trigger endpoint being publicly accessible and passing the full HTTP request body into automation execution parameters. This allows attackers to exploit a mass assignment vulnerability in externalTrigger() by including the internal appId property in the webhook POST body. Conseq [truncated]
CVE-2026-54350 is a critical vulnerability in Budibase, an open-source low-code platform. Prior to version 3.39.12, an unauthenticated visitor of any published Budibase app can read every document of the backing MongoDB, CouchDB, Elasticsearch, DynamoDB-PartiQL, or REST-with-JSON-body collection. If the builder has published a PUBLIC write query, the visitor can also modify every document of that collecti [truncated]
CVE-2026-50137 is a high-severity vulnerability in Budibase, an open-source low-code platform. An attacker can exploit this vulnerability to obtain a pre-signed PUT URL, allowing them to write to any bucket that the victim's IAM credentials can write to. The vulnerability exists in the Budibase server route POST /api/attachments/:datasourceId/url, which is registered with only the recaptcha middleware and [truncated]
CVE-2026-50136 is a HIGH severity vulnerability in Budibase, an open-source low-code platform. Prior to version 3.39.3, Budibase exposes an unauthenticated endpoint that generates S3 PutObject presigned URLs using credentials stored in a workspace datasource. This endpoint is only protected by the recaptcha middleware and does not require authentication, table permission, datasource permission, or builder [truncated]
A Server-Side Request Forgery (SSRF) vulnerability exists in Budibase's OAuth2 SDK prior to version 3.39.0. The `fetchToken` function makes POST requests to builder-supplied URLs using plain `node-fetch` without applying the `blacklist.isBlacklisted` check that protects other outbound fetch paths in the codebase. Additionally, the Joi schema for OAuth2 URLs lacks scheme or host restrictions, allowing atta [truncated]
A privilege escalation vulnerability in Budibase prior to version 3.39.0 allows Basic app users to exfiltrate REST datasource authorization secrets. The issue stems from insufficient access controls on single-datasource GET and PUT endpoints, which rely on generic TABLE READ permissions rather than Builder/Admin-specific or datasource-ownership checks. The Basic role's WRITE permission set includes table [truncated]
A missing authorization check in Budibase's webhook schema-building endpoint allows unauthenticated attackers to modify webhook body schemas and automation trigger output schemas. The vulnerability exists because the `/api/webhooks/schema` path is registered under `builderRoutes` but the generic authorization middleware explicitly skips authorization for this path pattern. This architectural gap permits a [truncated]
A critical privilege escalation vulnerability in Budibase allows workspace-scoped builders to grant themselves or others global administrator privileges. The flaw exists in the /api/public/v1/roles/assign endpoint, where the builderOrAdmin middleware permits access based on app-level builder status, but the underlying SDK grants global roles without additional verification. An attacker with workspace-scop [truncated]
A stored cross-site scripting (XSS) vulnerability exists in Budibase, an open-source low-code platform, affecting versions prior to 3.39.0. The vulnerability resides in the Text component's Markdown rendering functionality, where user-supplied markdown content is parsed and assigned directly to innerHTML without sanitization. Any application user with WRITE permissions on a table can inject malicious payl [truncated]
## Summary Budibase versions prior to 3.35.3 contain a server-side request forgery (SSRF) vulnerability in the VectorDB configuration endpoint. The endpoint accepts a host parameter without validation against internal IP ranges, reserved hostnames, or URL schemes. An authenticated user with builder-level access can supply arbitrary host values—including cloud metadata endpoints (169.254.169.254) or localh [truncated]
A cross-site request forgery (CSRF) bypass vulnerability exists in Budibase prior to version 3.35.4. The root cause is improper regular expression anchoring in the route matching logic used by CSRF middleware. The `buildMatcherRegex()` and `matches()` functions in `packages/backend-core/src/middleware/matchers.ts` compile route patterns into unanchored regular expressions and match them against `ctx.reque [truncated]
CVE-2026-48146 is a Server-Side Request Forgery (SSRF) vulnerability in Budibase, an open-source low-code platform. The flaw exists in the OAuth2 token fetch function located in `packages/server/src/sdk/workspace/oauth2/utils.ts` prior to version 3.39.0. The vulnerable code uses a raw `fetch(config.url)` call without SSRF protection, despite the existence of a `fetchWithBlacklist()` wrapper elsewhere in t [truncated]
CVE-2026-48128 is a server-side request forgery (SSRF) vulnerability in Budibase, an open-source low-code platform. The issue exists in the executeQuery automation step prior to version 3.39.0. The automation step accepts a queryId from user-controlled inputs and passes it directly to the query execution controller without validation. When a REST datasource is configured to target internal infrastructure, [truncated]
A stored cross-site scripting (XSS) vulnerability exists in Budibase, an open-source low-code platform, affecting versions prior to 3.38.2. The file upload endpoint POST /api/attachments/process fails to enforce active-content restrictions for authenticated builder users. Dangerous file extension checks are conditionally bypassed when the user is not a public user or when the environment is self-hosted. T [truncated]
A critical authorization bypass vulnerability in Budibase's SCIM (System for Cross-domain Identity Management) implementation allows any authenticated user to perform full CRUD operations on all users and groups within a tenant. The vulnerability exists because the SCIM router in packages/worker/src/api/routes/global/scim.ts only applies two middleware checks—requireSCIM (Enterprise feature flag and SCIM [truncated]
Budibase is an open-source low-code platform. Prior to 3.38.2, the public API role unassignment endpoint (POST /api/public/v1/roles/unassign) updates user documents in CouchDB but does not invalidate the corresponding Redis user cache entries. Because the authentication middleware resolves user identity and permissions from this cache (TTL: 3600 seconds), a user whose admin, builder, or app-level roles ha [truncated]
## Summary Budibase versions prior to 3.38.1 contain a server-side code injection vulnerability in the V1 Views API. The `POST /api/views` endpoint accepts a `calculation` parameter that is interpolated directly into a CouchDB reduce function definition without validation, despite the existence of an internal `SCHEMA_MAP` object that defines valid calculation types (`sum`, `count`, `stats`). A user with B [truncated]
Budibase is an open-source low-code platform. Prior to 3.38.1, the row action trigger endpoint (POST /api/tables/:sourceId/actions/:actionId/trigger) fails to validate that the user-supplied rowId is within the scope of the view's row filters. A user with access to a filtered view can trigger row actions on any row in the underlying table, including rows explicitly excluded by the view's security filters. [truncated]
**Executive Summary:** Budibase versions prior to 3.38.1 contain a broken access control vulnerability (CWE-862) that allows any authenticated non-builder application user to modify datasource configurations. The PUT /api/datasources/:datasourceId endpoint was incorrectly assigned TABLE/READ permission level—equivalent to the read endpoint—rather than requiring elevated builder privileges. Since all authe [truncated]