npm1 critical
@budibase/backend-core
2 known vulnerabilities · 1 critical · 0 high
GHSA-8783-3wgf-jggf
Budibase: Authentication Bypass via Unanchored Regex in Public Endpoint Matcher — Unauthenticated Access to Protected Endpoints
Published Apr 16, 2026
CVE-2026-31818CRITICAL
Risk: 48/100
Budibase: Server-Side Request Forgery via REST Connector with Empty Default Blacklist
Published Apr 3, 2026
Check your entire dependency tree at onceRun dependency scan →