9

CVE-2026-35216

Exploit

Budibase: Unauthenticated Remote Code Execution via Webhook Trigger and Bash Automation Step

Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) on the Budibase server by triggering an automation that contains a Bash step via the public webhook endpoint. No authentication is required to trigger the exploit. The process executes as root inside the container. This issue has been patched in version 3.33.4.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BudibaseBudibase Version < 3.33.4
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 11.98% 0.956
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 9 2.2 6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

https://github.com/Budibase/budibase/releases/tag/3.33.4
Product
Release Notes
https://github.com/Budibase/budibase/security/advisories/GHSA-fcm4-4pj2-m5hf
Vendor Advisory
Exploit
https://github.com/Budibase/budibase/pull/18238
Patch
Issue Tracking
https://github.com/Budibase/budibase/commit/f0c731b409a96e401445a6a6030d2994ff4ac256
Patch