OsVault/npm/@budibase/server
npm1 critical

@budibase/server

13 known vulnerabilities · 1 critical · 1 high

CVE-2026-25044
Risk: 0.02/100

Budibase: Command Injection in Bash Automation Step

Published Apr 3, 2026
CVE-2026-25041

@budibase/server: Command Injection in PostgreSQL Dump Command

Published Mar 9, 2026
CVE-2026-35216CRITICAL
Risk: 45.1/100

Budibase: Unauthenticated Remote Code Execution via Webhook Trigger and Bash Automation Step

Published Apr 4, 2026
GHSA-44m2-crh7-f4q2

Budibase: `PUT /api/datasources/:datasourceId` is protected only by `TABLE/READ` permission instead of builder access, allowing any authenticated app user to overwrite datasource connection parameters including host, port, and URL

Published May 15, 2026
GHSA-fgqv-jh4g-pvg2

Budibase: SSRF Bypass via HTTP Redirect in REST Datasource Integration

Published May 15, 2026
GHSA-rpj4-7x2v-wjrf

Budibase: SSRF in AI Extract File Automation Step via Missing IP Blacklist Validation

Published May 15, 2026
GHSA-363w-hvwh-w7m6

Budibase: CouchDB Reduce Injection via Unsanitized Calculation Parameter in V1 Views API

Published May 18, 2026
CVE-2026-35214HIGH
Risk: 43.53/100

Budibase: Path traversal in plugin file upload enables arbitrary directory deletion and file write

Published Apr 4, 2026
GHSA-3gp5-q4jw-3v94

Budibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasource base URL

Published Jun 12, 2026
GHSA-6xp4-cf37-ppjh

Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign

Published Jun 12, 2026
GHSA-cv96-5348-p5p8

Budibase: Unvalidated VectorDB Host Parameter Enables SSRF

Published Jun 12, 2026
GHSA-g6qx-g4pr-92v7

Budibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist Protection

Published Jun 12, 2026
GHSA-qhv3-wjg8-6fx6

Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schema

Published Jun 12, 2026
Check your entire dependency tree at onceRun dependency scan →