Budibase

Budibase

66 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 01.08.2026 12:22:18
  • Zuletzt bearbeitet 03.08.2026 16:16:30

Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that fails to validate HTTP redirects against the IP blacklist. Attackers with Builder role can configure a REST datasource pointing to an ...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 26.06.2026 20:45:35
  • Zuletzt bearbeitet 30.06.2026 19:52:17

Budibase is an open-source low-code platform. Prior to 3.39.9, the webhook trigger endpoint in Budibase is publicly accessible and passes the full HTTP request body into automation execution parameters. A mass assignment vulnerability in externalTrig...

Exploit
  • EPSS 0.16%
  • Veröffentlicht 26.06.2026 20:44:52
  • Zuletzt bearbeitet 30.06.2026 20:05:11

Budibase is an open-source low-code platform. Prior to 3.39.9, authenticated users with automation permissions can bypass Budibase's SSRF blacklist through DNS rebinding. The outbound fetch flow validates a hostname against the blacklist before the r...

Exploit
  • EPSS 0.47%
  • Veröffentlicht 26.06.2026 20:44:00
  • Zuletzt bearbeitet 30.06.2026 20:17:30

Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor of any published Budibase app reads every document of the backing MongoDB, CouchDB, Elasticsearch, DynamoDB-PartiQL, or REST-with-JSON-body collection and, wh...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 26.06.2026 20:41:03
  • Zuletzt bearbeitet 30.06.2026 19:49:18

Budibase is an open-source low-code platform. Prior to 3.39.0, an anonymous attacker who knows or can enumerate a workspace id (app_...) and an S3-source datasource id (ds_...) can call this endpoint with no auth and obtain a 15-minute pre-signed PUT...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 26.06.2026 20:36:54
  • Zuletzt bearbeitet 30.06.2026 19:40:07

Budibase is an open-source low-code platform. Prior to 3.39.3, the application server exposes an unauthenticated endpoint that generates S3 PutObject presigned URLs using credentials stored in a workspace datasource. The route is protected only by th...

Exploit
  • EPSS 0.15%
  • Veröffentlicht 26.06.2026 20:34:30
  • Zuletzt bearbeitet 30.06.2026 19:26:42

Budibase is an open-source low-code platform. Prior to 3.39.0, `GET /api/chat-links/:instance/:token/handoff` is a public endpoint (no auth required) that performs a permanent, state-changing operation: it binds an external chat identity (Slack/Disco...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 26.06.2026 20:32:51
  • Zuletzt bearbeitet 30.06.2026 20:00:57

Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at packages/server/src/api/routes/static.ts:24 accepts a builder-uploaded .zip, extracts it with extract-zip@2.0.1 into a temp directory, then for each entry l...

  • EPSS 0.12%
  • Veröffentlicht 27.05.2026 17:14:17
  • Zuletzt bearbeitet 27.05.2026 20:16:40

Budibase is an open-source low-code platform. Prior to 3.35.4, the buildMatcherRegex() / matches() functions in packages/backend-core/src/middleware/matchers.ts route patterns are compiled into unanchored regular expressions and tested against ctx.re...

  • EPSS 0.23%
  • Veröffentlicht 27.05.2026 17:12:31
  • Zuletzt bearbeitet 27.05.2026 19:44:35

Budibase is an open-source low-code platform. Prior to 3.35.3, the VectorDB configuration endpoint in Budibase accepts a host parameter that undergoes no validation against internal IP ranges, reserved hostnames, or URL schemes. Any authenticated us...