OsVault/npm/budibase
npm2 critical

budibase

27 known vulnerabilities · 2 critical · 2 high

CVE-2026-27702

Budibase: Remote Code Execution via Unsafe eval() in View Filter Map Function (Budibase Cloud)

Published Feb 25, 2026
CVE-2026-33226

Budibase Unrestricted Server-Side Request Forgery (SSRF) via REST Datasource Query Preview

Published Mar 18, 2026
GHSA-xh5j-727m-w6gg

Budibase vulnerable to SSRF via trivial `.tar.gz` substring bypass in Plugin URL upload (`/api/plugin`)

Published May 11, 2026
GHSA-82rc-gxrg-v4gf

Budibase: Unrestricted Upload of File with Dangerous Type

Published May 19, 2026
GHSA-3263-v5v9-xq8q

Budibase: Row Action Trigger Bypasses View Row Filter Security Boundary Allowing Action on Out-of-Scope Rows

Published May 18, 2026
GHSA-6964-pp88-6wp9

Budibase: SSRF via User-Controlled queryId in Automation Execute Query Step

Published Jun 12, 2026
GHSA-qqf5-x7mj-v43p

budibase: Database Connector SQL Injections in PostgreSQL, MS SQL, and MySQL

Published Jun 18, 2026
GHSA-6vp2-6r7m-2jvx

Budibase: Missing Cache Invalidation on Public API Role Unassignment Allows Revoked Users to Retain Privileges for Up to 1 Hour

Published May 19, 2026
GHSA-8783-3wgf-jggf

Budibase: Authentication Bypass via Unanchored Regex in Public Endpoint Matcher — Unauthenticated Access to Protected Endpoints

Published Apr 16, 2026
GHSA-wxq7-x3qp-vcr8

Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Worker

Published Jun 12, 2026
CVE-2026-25044
Risk: 0.02/100

Budibase: Command Injection in Bash Automation Step

Published Apr 3, 2026
CVE-2026-25041

@budibase/server: Command Injection in PostgreSQL Dump Command

Published Mar 9, 2026
CVE-2022-3225HIGH

Budibase Improper Control of Dynamically-Managed Code Resources vulnerability

Published Sep 17, 2022
CVE-2026-35216CRITICAL
Risk: 45.1/100

Budibase: Unauthenticated Remote Code Execution via Webhook Trigger and Bash Automation Step

Published Apr 4, 2026
GHSA-4f9j-vr4p-642r

Budibase auth session cookies are set with httpOnly:false — any XSS can lead to full account takeover

Published Apr 24, 2026
GHSA-44m2-crh7-f4q2

Budibase: `PUT /api/datasources/:datasourceId` is protected only by `TABLE/READ` permission instead of builder access, allowing any authenticated app user to overwrite datasource connection parameters including host, port, and URL

Published May 15, 2026
CVE-2026-31818CRITICAL
Risk: 48/100

Budibase: Server-Side Request Forgery via REST Connector with Empty Default Blacklist

Published Apr 3, 2026
GHSA-fgqv-jh4g-pvg2

Budibase: SSRF Bypass via HTTP Redirect in REST Datasource Integration

Published May 15, 2026
GHSA-rpj4-7x2v-wjrf

Budibase: SSRF in AI Extract File Automation Step via Missing IP Blacklist Validation

Published May 15, 2026
GHSA-c54j-xp92-wh28

Budibase: Builder-to-Admin Privilege Escalation via onboardUsers Endpoint Without SMTP Configuration

Published May 18, 2026
GHSA-363w-hvwh-w7m6

Budibase: CouchDB Reduce Injection via Unsanitized Calculation Parameter in V1 Views API

Published May 18, 2026
CVE-2026-35214HIGH
Risk: 43.53/100

Budibase: Path traversal in plugin file upload enables arbitrary directory deletion and file write

Published Apr 4, 2026
GHSA-3gp5-q4jw-3v94

Budibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasource base URL

Published Jun 12, 2026
GHSA-6xp4-cf37-ppjh

Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign

Published Jun 12, 2026
GHSA-cv96-5348-p5p8

Budibase: Unvalidated VectorDB Host Parameter Enables SSRF

Published Jun 12, 2026
GHSA-g6qx-g4pr-92v7

Budibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist Protection

Published Jun 12, 2026
GHSA-qhv3-wjg8-6fx6

Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schema

Published Jun 12, 2026
Check your entire dependency tree at onceRun dependency scan →