npm

@budibase/server

View on npm registry
42 Total advisories
42 Vulnerabilities
0 Malware

Dependency scanning

Check whether @budibase/server is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

HIGH 7.1
npm

CVE-2026-54356

Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url`

MEDIUM 4.9
npm

CVE-2026-73304

Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users

HIGH 7.7
npm

CVE-2026-72859

Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLs

UNKNOWN
npm

CVE-2026-35219

Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist

HIGH 8.5
npm

CVE-2026-72855

Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution

HIGH 8.3
npm

CVE-2026-73618

Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution

HIGH 7.7
npm

CVE-2026-72849

Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)

HIGH 7.1
npm

CVE-2026-73617

Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete

HIGH 7.6
npm

CVE-2026-73408

Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector

UNKNOWN
npm

CVE-2026-73407

Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak

UNKNOWN
npm

CVE-2026-73409

Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile

HIGH 8.5
npm

CVE-2026-73410

Budibase: SSRF via DNS rebinding in the REST datasource integration

MEDIUM 5.7
npm

CVE-2026-73308

Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders

UNKNOWN
npm

CVE-2026-73307

Budibase: SSRF via bare fetch() in uploadUrl during AI table generation

HIGH 7.5
npm

CVE-2026-73406

Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint

CRITICAL 9.6
npm

CVE-2026-73300

Budibase: SQL Injection via `multipleStatements: true`

MEDIUM 5.3
npm

CVE-2026-73306

Budibase: Account Enumeration via Login Lockout Response Differential

CRITICAL 10.0
npm

CVE-2026-54350

Budibase has nonymous NoSQL operator injection via published-app query templates

CRITICAL 9.6
npm

CVE-2026-54352

Budibase has arbitrary file read by workspace-builder via PWA-zip symlink upload

HIGH 8.8
npm

CVE-2026-73305

Budibase: Privilege escalation via public role assignment API missing app-level authorization

UNKNOWN
npm

CVE-2026-73302

Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified

UNKNOWN
npm

CVE-2026-73303

Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)

MEDIUM 4.3
npm

CVE-2026-73301

Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings

HIGH 7.3
npm

CVE-2026-50132

Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF

HIGH 8.2
npm

CVE-2026-54351

Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Override

CRITICAL 9.4
npm

CVE-2026-50137

Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentials

HIGH 7.4
npm

CVE-2026-50136

Budibase: Unauthenticated S3 signed upload URL generation allows arbitrary writes with stored datasource credentials

HIGH 8.5
npm

CVE-2026-48153

Budibase: SSRF via OAuth2 token endpoint URL reaches internal hosts and cloud metadata

CRITICAL 9.0
npm

CVE-2026-48150

Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign

UNKNOWN
npm

CVE-2026-48148

Budibase: Unvalidated VectorDB Host Parameter Enables SSRF

HIGH 7.5
npm

CVE-2026-48151

Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schema

HIGH 8.1
npm

CVE-2026-48152

Budibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasource base URL

HIGH 7.7
npm

CVE-2026-48146

Budibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist Protection

HIGH 7.7
npm

CVE-2026-45548

Budibase: SSRF in AI Extract File Automation Step via Missing IP Blacklist Validation

HIGH 8.8
npm

CVE-2026-45717

Budibase: `PUT /api/datasources/:datasourceId` is protected only by `TABLE/READ` permission instead of builder access, allowing any authenticated app user to overwrite datasource connection parameters including host, port, and URL

MEDIUM 6.5
npm

CVE-2026-45719

Budibase: CouchDB Reduce Injection via Unsanitized Calculation Parameter in V1 Views API

HIGH 7.7
npm

CVE-2026-45715

Budibase: SSRF Bypass via HTTP Redirect in REST Datasource Integration

HIGH 8.8
npm

CVE-2026-25044

Budibase: Command Injection in Bash Automation Step

CRITICAL 9.0
npm

CVE-2026-35216

Budibase: Unauthenticated Remote Code Execution via Webhook Trigger and Bash Automation Step

HIGH 8.7
npm

CVE-2026-35214

Budibase: Path traversal in plugin file upload enables arbitrary directory deletion and file write

UNKNOWN
npm

CVE-2026-25041

@budibase/server: Command Injection in PostgreSQL Dump Command

CRITICAL 9.8
npm

GHSA-4g2x-vq5p-5vj6

Budibase affected by VM2 Constructor Escape Vulnerability

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes