Budibase

Budibase

67 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 01.10.2026 10:42:25
  • Zuletzt bearbeitet 01.10.2026 14:17:28

Budibase through 3.41.0 contains a server-side request forgery vulnerability in AI table generation because the uploadUrl function in packages/server/src/utilities/fileUtils.ts uses raw node-fetch instead of fetchWithBlacklist. Authenticated builder ...

  • EPSS 0.35%
  • Veröffentlicht 17.08.2026 20:32:05
  • Zuletzt bearbeitet 08.09.2026 21:03:08

Budibase is an open-source low-code platform. Prior to 3.41.3, POST /api/attachments/:datasourceId/url in packages/server/src/api/routes/static.ts and packages/server/src/api/controllers/static/index.ts allows an authenticated published-app user with...

  • EPSS 0.47%
  • Veröffentlicht 17.08.2026 20:28:40
  • Zuletzt bearbeitet 08.09.2026 21:03:08

Budibase is an open-source low-code platform. Prior to 3.41.3, automation steps in packages/server/src/automations/steps/outgoingWebhook.ts, packages/server/src/automations/steps/zapier.ts, packages/server/src/automations/steps/n8n.ts, packages/serve...

  • EPSS 0.17%
  • Veröffentlicht 17.08.2026 20:27:24
  • Zuletzt bearbeitet 08.09.2026 21:03:08

Budibase is an open-source low-code platform. Prior to 3.40.0, packages/backend-core/src/utils/outboundFetch.ts pinned a validated address through a Node agent, but the REST integration used getDispatcher from packages/backend-core/src/utils/fetch.ts...

  • EPSS 0.24%
  • Veröffentlicht 17.08.2026 20:24:59
  • Zuletzt bearbeitet 08.09.2026 21:03:08

Budibase is an open-source low-code platform. Prior to 3.39.19, the PostgreSQL datasource connector in packages/server/src/integrations/postgres.ts interpolates the user-controlled schema configuration field into a SET search_path statement without e...

  • EPSS 0.37%
  • Veröffentlicht 13.08.2026 22:05:02
  • Zuletzt bearbeitet 08.09.2026 20:56:50

Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRoleUpdate without checking appBuilder.appId or role.appId in packages/server/src/api/controllers/public/globalRoleValidation.ts. An...

  • EPSS 0.36%
  • Veröffentlicht 13.08.2026 22:05:00
  • Zuletzt bearbeitet 08.09.2026 20:56:50

Budibase is an open-source low-code platform. Prior to 3.39.25, GET /api/users/metadata and GET /api/users/metadata/:id returned user objects processed by packages/server/src/utilities/global.ts without removing oauth2.accessToken or oauth2.refreshTo...

  • EPSS 0.33%
  • Veröffentlicht 13.08.2026 22:04:53
  • Zuletzt bearbeitet 08.09.2026 20:56:50

Budibase is an open-source low-code platform. Prior to 3.39.18, packages/server/src/integrations/mysql.ts enabled multipleStatements and inserted an unescaped tableName into a DESCRIBE statement. An attacker able to create a MySQL table with a backti...

  • EPSS 0.31%
  • Veröffentlicht 13.08.2026 22:04:50
  • Zuletzt bearbeitet 08.09.2026 20:56:50

Budibase is an open-source low-code platform. Prior to 3.39.30, the OIDC flow in packages/backend-core/src/middleware/passport/sso/oidc.ts resolved an email without getEmailVerified or an email_verified requirement, and packages/backend-core/src/midd...

  • EPSS 0.26%
  • Veröffentlicht 13.08.2026 21:54:45
  • Zuletzt bearbeitet 31.08.2026 20:33:07

Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowing authenticated users to read MongoDB connection strings and Firebase private keys in plaintext. Attackers with table read permissions can retrieve da...