Security: Budibase/budibase
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Budibase 3.39.7 authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url`GHSA-6x9p-4r67-5gjx published
Aug 14, 2026 by mjashanksHigh -
Unauthenticated user information disclosure via public tenant user lookup endpointGHSA-hr66-5mqr-8mpx published
Jul 22, 2026 by mjashanksHigh -
S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLsGHSA-xcx6-4f2g-hhgx published
Jul 22, 2026 by mjashanksHigh -
Potential SSRF DNS rebinding bypass in outbound fetch validationGHSA-gfq7-5x4g-3xhf published
Jun 4, 2026 by mjashanksHigh -
SSRF via bare fetch() in uploadUrl during AI table generationGHSA-hfhx-w8p8-4hc7 published
Jul 22, 2026 by mjashanksModerate -
Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappingsGHSA-4qcj-m5wp-jmf4 published
Jul 22, 2026 by mjashanksModerate -
Arbitrary file read by workspace-builder via PWA-zip symlink uploadGHSA-w7mq-r738-x278 published
Jun 4, 2026 by mjashanksCritical -
Anonymous NoSQL operator injection via published-app query templatesGHSA-8qv3-p479-cj62 published
Jun 11, 2026 by mjashanksCritical -
Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentialsGHSA-35c4-rvc8-frhm published
May 28, 2026 by mjashanksHigh -
Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schemaGHSA-qhv3-wjg8-6fx6 published
May 21, 2026 by mjashanksHigh