CVE-2026-67311
- EPSS 0.26%
- Veröffentlicht 01.08.2026 12:22:18
- Zuletzt bearbeitet 03.08.2026 16:16:30
Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that fails to validate HTTP redirects against the IP blacklist. Attackers with Builder role can configure a REST datasource pointing to an ...
CVE-2026-54351
- EPSS 0.33%
- Veröffentlicht 26.06.2026 20:45:35
- Zuletzt bearbeitet 30.06.2026 19:52:17
Budibase is an open-source low-code platform. Prior to 3.39.9, the webhook trigger endpoint in Budibase is publicly accessible and passes the full HTTP request body into automation execution parameters. A mass assignment vulnerability in externalTrig...
CVE-2026-54353
- EPSS 0.16%
- Veröffentlicht 26.06.2026 20:44:52
- Zuletzt bearbeitet 30.06.2026 20:05:11
Budibase is an open-source low-code platform. Prior to 3.39.9, authenticated users with automation permissions can bypass Budibase's SSRF blacklist through DNS rebinding. The outbound fetch flow validates a hostname against the blacklist before the r...
CVE-2026-54350
- EPSS 0.47%
- Veröffentlicht 26.06.2026 20:44:00
- Zuletzt bearbeitet 30.06.2026 20:17:30
Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor of any published Budibase app reads every document of the backing MongoDB, CouchDB, Elasticsearch, DynamoDB-PartiQL, or REST-with-JSON-body collection and, wh...
CVE-2026-50137
- EPSS 0.3%
- Veröffentlicht 26.06.2026 20:41:03
- Zuletzt bearbeitet 30.06.2026 19:49:18
Budibase is an open-source low-code platform. Prior to 3.39.0, an anonymous attacker who knows or can enumerate a workspace id (app_...) and an S3-source datasource id (ds_...) can call this endpoint with no auth and obtain a 15-minute pre-signed PUT...
CVE-2026-50136
- EPSS 0.2%
- Veröffentlicht 26.06.2026 20:36:54
- Zuletzt bearbeitet 30.06.2026 19:40:07
Budibase is an open-source low-code platform. Prior to 3.39.3, the application server exposes an unauthenticated endpoint that generates S3 PutObject presigned URLs using credentials stored in a workspace datasource. The route is protected only by th...
CVE-2026-50132
- EPSS 0.15%
- Veröffentlicht 26.06.2026 20:34:30
- Zuletzt bearbeitet 30.06.2026 19:26:42
Budibase is an open-source low-code platform. Prior to 3.39.0, `GET /api/chat-links/:instance/:token/handoff` is a public endpoint (no auth required) that performs a permanent, state-changing operation: it binds an external chat identity (Slack/Disco...
CVE-2026-54352
- EPSS 0.37%
- Veröffentlicht 26.06.2026 20:32:51
- Zuletzt bearbeitet 30.06.2026 20:00:57
Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at packages/server/src/api/routes/static.ts:24 accepts a builder-uploaded .zip, extracts it with extract-zip@2.0.1 into a temp directory, then for each entry l...
CVE-2026-48147
- EPSS 0.12%
- Veröffentlicht 27.05.2026 17:14:17
- Zuletzt bearbeitet 27.05.2026 20:16:40
Budibase is an open-source low-code platform. Prior to 3.35.4, the buildMatcherRegex() / matches() functions in packages/backend-core/src/middleware/matchers.ts route patterns are compiled into unanchored regular expressions and tested against ctx.re...
CVE-2026-48148
- EPSS 0.23%
- Veröffentlicht 27.05.2026 17:12:31
- Zuletzt bearbeitet 27.05.2026 19:44:35
Budibase is an open-source low-code platform. Prior to 3.35.3, the VectorDB configuration endpoint in Budibase accepts a host parameter that undergoes no validation against internal IP ranges, reserved hostnames, or URL schemes. Any authenticated us...