PatchSiren

budibase CVE debriefs · Page 3

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Budibase CVE published 2026-05-27

CVE-2026-45716

A privilege escalation vulnerability in Budibase, an open-source low-code platform, allows builder-level users to create global admin accounts when SMTP email is not configured. The POST /api/global/users/onboard endpoint, protected only by workspaceBuilderOrAdmin middleware, accepts arbitrary role assignments in the request body and returns generated passwords in the response. This bypasses the intended [truncated]

HIGH Budibase CVE published 2026-05-27

CVE-2026-45715

Budibase versions prior to 3.38.1 contain a Server-Side Request Forgery (SSRF) vulnerability in the REST datasource integration. The application follows HTTP redirects without re-validating the destination IP address against the configured blacklist, enabling an authenticated Builder to access internal services—including cloud metadata endpoints and databases—by redirecting requests through an attacker-co [truncated]

HIGH Budibase CVE published 2026-05-27

CVE-2026-45548

CVE-2026-45548 is a server-side request forgery (SSRF) vulnerability in Budibase, an open-source low-code platform. The flaw exists in the `processUrlFile` function within `packages/server/src/automations/steps/ai/extract.ts`, which performs direct `fetch(fileUrl)` calls without applying IP blacklist validation. This validation is consistently enforced across all other automation steps but was omitted in [truncated]

HIGH Budibase CVE published 2026-05-27

CVE-2026-45061

CVE-2026-45061 is a high-severity (CVSS 7.7) Server-Side Request Forgery (SSRF) vulnerability in Budibase, an open-source low-code platform. The flaw exists in the Plugin URL upload endpoint (POST /api/plugin) prior to version 3.35.10. The endpoint performs insufficient URL validation using only a substring check for `.tar.gz`, which can appear anywhere in the URL string—including query parameters or frag [truncated]

HIGH Budibase CVE published 2026-05-07

CVE-2026-42239

CVE-2026-42239 is a high-severity vulnerability in Budibase, an open-source low-code platform. The issue arises from the insecure setting of the `budibase:auth` cookie, which contains the JWT session token. Specifically, the cookie is set with `httpOnly: false`, allowing JavaScript to access it via `document.cookie`. This makes every cross-site scripting (XSS) vulnerability a full account takeover, as an [truncated]

CRITICAL Budibase CVE published 2026-04-03

CVE-2026-35216

CVE-2026-35216 is a critical vulnerability in Budibase, an open-source low-code platform. An unauthenticated attacker can achieve Remote Code Execution (RCE) on the Budibase server by triggering an automation that contains a Bash step via the public webhook endpoint. No authentication is required to trigger the exploit. The process executes as root inside the container. This issue has been patched in vers [truncated]

HIGH Budibase CVE published 2026-04-03

CVE-2026-35214

CVE-2026-35214 is a high-severity vulnerability in Budibase, an open-source low-code platform. The plugin file upload endpoint (POST /api/plugin/upload) is vulnerable to path traversal, allowing an attacker with Global Builder privileges to delete arbitrary directories and write arbitrary files via tarball extraction to any filesystem path the Node.js process can access. This issue has been patched in ver [truncated]

CRITICAL Budibase CVE published 2026-04-03

CVE-2026-31818

Budibase, an open-source low-code platform, had a server-side request forgery (SSRF) vulnerability prior to version 3.33.4. The platform's SSRF protection mechanism, which relies on an IP blacklist defined by the BLACKLIST_IPS environment variable, was ineffective by default in official deployment configurations. This allowed unauthorized requests to pass through without restriction. The issue was patched [truncated]

HIGH Budibase CVE published 2026-04-03

CVE-2026-25044

CVE-2026-25044 is a high-severity vulnerability in Budibase, an open-source low-code platform. The bash automation step executes user-provided commands without proper sanitization or validation, potentially allowing arbitrary command execution. This issue has been patched in version 3.33.4. Budibase users and administrators should be aware of this vulnerability and take immediate action to upgrade or appl [truncated]

MEDIUM Budibase CVE published 2026-04-03

CVE-2026-25043

CVE-2026-25043 is a business logic vulnerability in Budibase’s password reset functionality prior to version 3.23.25. The vulnerability allows an unauthenticated attacker to repeatedly trigger password reset requests for the same email address, resulting in hundreds of password reset emails being sent in a short time window. This enables large-scale email flooding, user harassment, denial of service (DoS) [truncated]