Security: Budibase/budibase
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Authentication Bypass via Unanchored Regex in Public Endpoint Matcher — Unauthenticated Access to Protected EndpointsGHSA-8783-3wgf-jggf published
Apr 16, 2026 by mjashanksCritical -
Auth session cookie set with httpOnly:false — any XSS leads to full account takeoverGHSA-4f9j-vr4p-642r published
Apr 21, 2026 by mjashanksHigh -
Missing Cache Invalidation on Public API Role Unassignment Allows Revoked Users to Retain Privileges for Up to 1 HourGHSA-6vp2-6r7m-2jvx published
May 14, 2026 by mjashanksModerate -
SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role UsersGHSA-fcrw-f7gg-6g9f published
Jul 22, 2026 by mjashanksModerate -
Account Enumeration via Login Lockout Response Differential in BudibaseGHSA-cr7p-cr3q-h5cm published
Jul 22, 2026 by mjashanksModerate -
Row Action Trigger Bypasses View Row Filter Security Boundary Allowing Action on Out-of-Scope RowsGHSA-3263-v5v9-xq8q published
May 12, 2026 by mjashanksModerate -
OAuth2 Token Disclosure via Automation Test Results Broadcast to Other BuildersGHSA-gh4h-34gr-87r7 published
Jul 22, 2026 by mjashanksModerate -
SSRF with Internal CouchDB Credential Leakage via Datasource Verify EndpointGHSA-83m5-fvmg-r7xv published
Aug 14, 2026 by mjashanksHigh -
Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId OverrideGHSA-rgvg-3wpc-h44p published
Jun 4, 2026 by mjashanksHigh -
Builder-to-Admin Privilege Escalation via onboardUsers Endpoint Without SMTP ConfigurationGHSA-c54j-xp92-wh28 published
May 12, 2026 by mjashanksHigh