Vulnerabilities in Budibase
46 resultsVexday analysis
Budibase apresenta volume elevado de vulnerabilidades (44 CVEs), com 29 publicadas nos últimos 90 dias, indicando ritmo acelerado de descobertas. Não há exploração ativa documentada (0 KEV), mas 10 vulnerabilidades críticas foram registradas, predominantemente relacionadas a requisições HTTP não validadas (CWE-918), padrão típico de plataformas web. O risco é substancial em gravidade potencial, embora atualmente sem evidência de aproveitamento em campo.
CVE-2026-25045HIGHBudibase Critical Privilege Escalation & IDOR via Missing RBAC on User Role Management (Creator-Role)EPSS 0.3%CVE-2026-46425CRITICALBudibase: SCIM endpoints lack role-based authorization, BASIC users CRUD tenant usersEPSS 0.3%CVE-2026-42239HIGHBudibase auth session cookies are set with httpOnly:false — any XSS can lead to full account takeoverEPSS 0.3%CVE-2026-30240CRITICALBudibase PWA ZIP Upload Path Traversal Allows Reading Arbitrary Server Files Including All Environment SecretsEPSS 0.3%CVE-2026-25737HIGHBudibase Arbitrary File Upload Leading to Multiple Critical Vulnerabilities (SSRF, Stored XSS)EPSS 0.3%CVE-2026-45719MEDIUMBudibase: CouchDB Reduce Injection via Unsanitized Calculation Parameter in V1 Views APIEPSS 0.3%CVE-2026-45061HIGHBudibase: SSRF via trivial `.tar.gz` substring bypass in Plugin URL upload (`/api/plugin`)EPSS 0.3%CVE-2026-45716HIGHBudibase: Builder-to-Admin Privilege Escalation via onboardUsers Endpoint Without SMTP ConfigurationEPSS 0.3%CVE-2026-45715HIGHBudibase: SSRF Bypass via HTTP Redirect in REST Datasource IntegrationEPSS 0.3%CVE-2026-45548HIGHBudibase: SSRF in AI Extract File Automation Step via Missing IP Blacklist ValidationEPSS 0.3%CVE-2026-48152HIGHBudibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasource base URLEPSS 0.3%CVE-2026-67311HIGHBudibase before 3.38.1 SSRF Blacklist Bypass via HTTP RedirectEPSS 0.3%CVE-2026-45717HIGHBudibase: `PUT /api/datasources/:datasourceId` is protected only by `TABLE/READ` permission instead of builder access, allowing any authenticated app user to overwrite datasource connection parameters including host, port, and URL.EPSS 0.3%CVE-2026-48148MEDIUMBudibase: Unvalidated VectorDB Host Parameter Enables SSRFEPSS 0.2%CVE-2026-48149HIGHBudibase: Stored XSS in Text component: BASIC users execute JS in admin session via MarkdownViewer innerHTML + CDN+srcdoc CSP bypassEPSS 0.2%CVE-2026-48151HIGHBudibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schemaEPSS 0.2%CVE-2026-46427HIGHBudibase: Snowflake private key returned unmasked from datasource API to BASIC usersEPSS 0.2%CVE-2026-48146HIGHBudibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist ProtectionEPSS 0.2%CVE-2026-50136HIGHBudibase: Unauthenticated S3 signed upload URL generation allows arbitrary writes with stored datasource credentialsEPSS 0.2%CVE-2026-46426HIGHBudibase: Unrestricted Upload of File with Dangerous TypeEPSS 0.2%