CVE-2026-45548
- EPSS 0.26%
- Veröffentlicht 27.05.2026 17:11:42
- Zuletzt bearbeitet 27.05.2026 20:16:39
Budibase is an open-source low-code platform. Prior to 3.34.8, the processUrlFile function in packages/server/src/automations/steps/ai/extract.ts uses fetch(fileUrl) directly without the IP blacklist validation that is consistently applied to all oth...
CVE-2026-45715
- EPSS 0.26%
- Veröffentlicht 27.05.2026 17:10:53
- Zuletzt bearbeitet 28.05.2026 14:16:22
Budibase is an open-source low-code platform. Prior to 3.38.1, the REST datasource integration (packages/server/src/integrations/rest.ts) follows HTTP redirects without re-checking the IP blacklist, allowing an authenticated Builder to access interna...
CVE-2026-45716
- EPSS 0.26%
- Veröffentlicht 27.05.2026 17:09:43
- Zuletzt bearbeitet 27.05.2026 20:16:39
Budibase is an open-source low-code platform. Prior to 3.38.1, the POST /api/global/users/onboard endpoint is protected by workspaceBuilderOrAdmin middleware, allowing any user with builder permissions to access it. When SMTP email is not configured ...
CVE-2026-45717
- EPSS 0.25%
- Veröffentlicht 27.05.2026 17:09:06
- Zuletzt bearbeitet 27.05.2026 19:45:41
Budibase is an open-source low-code platform. Prior to 3.38.1, Budibase exposes a REST API for datasource management. The route PUT /api/datasources/:datasourceId is registered in the authorizedRoutes group with TABLE/READ permission. This is the sam...
CVE-2026-45718
- EPSS 0.15%
- Veröffentlicht 27.05.2026 17:07:59
- Zuletzt bearbeitet 28.05.2026 16:16:26
Budibase is an open-source low-code platform. Prior to 3.38.1, the row action trigger endpoint (POST /api/tables/:sourceId/actions/:actionId/trigger) fails to validate that the user-supplied rowId is within the scope of the view's row filters. A user...
CVE-2026-45719
- EPSS 0.26%
- Veröffentlicht 27.05.2026 17:07:20
- Zuletzt bearbeitet 27.05.2026 20:16:39
Budibase is an open-source low-code platform. Prior to 3.38.1, the V1 Views API (POST /api/views) accepts a calculation parameter from the request body that is interpolated directly into a CouchDB reduce function definition without validation. Althou...
CVE-2026-46425
- EPSS 0.29%
- Veröffentlicht 27.05.2026 17:06:36
- Zuletzt bearbeitet 28.05.2026 20:16:25
Budibase is an open-source low-code platform. Prior to 3.38.2, packages/worker/src/api/routes/global/scim.ts attaches only two middlewares to the SCIM router: requireSCIM (checks the Enterprise feature flag and SCIM config) and doInScimContext (sets ...
CVE-2026-46424
- EPSS 0.16%
- Veröffentlicht 27.05.2026 17:05:21
- Zuletzt bearbeitet 28.05.2026 16:16:27
Budibase is an open-source low-code platform. Prior to 3.38.2, the public API role unassignment endpoint (POST /api/public/v1/roles/unassign) updates user documents in CouchDB but does not invalidate the corresponding Redis user cache entries. Becaus...
CVE-2026-46426
- EPSS 0.18%
- Veröffentlicht 27.05.2026 17:04:42
- Zuletzt bearbeitet 27.05.2026 19:44:35
Budibase is an open-source low-code platform. Prior to 3.38.2, the file upload endpoint POST /api/attachments/process does not enforce active-content restrictions for authenticated users. The checks for dangerous file extensions are conditionally wra...
CVE-2026-46427
- EPSS 0.22%
- Veröffentlicht 27.05.2026 17:03:10
- Zuletzt bearbeitet 28.05.2026 16:16:27
Budibase is an open-source low-code platform. Prior to 3.38.3, removeSecrets at packages/server/src/sdk/workspace/datasources/datasources.ts masks only datasource config fields whose schema type is DatasourceFieldType.PASSWORD. The Snowflake integrat...