npm

@budibase/server

View on npm registry
40 Total advisories
40 Vulnerabilities
0 Malware

Vulnerabilities

HIGH 8.5
npm

GHSA-v42f-v8xc-j435

Budibase: SSRF via DNS rebinding in the REST datasource integration

UNKNOWN
npm

GHSA-hfhx-w8p8-4hc7

Budibase: SSRF via bare fetch() in uploadUrl during AI table generation

MEDIUM 5.3
npm

GHSA-cr7p-cr3q-h5cm

Budibase: Account Enumeration via Login Lockout Response Differential

HIGH 7.1
npm

GHSA-pmpg-2mxq-6xwr

Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete

HIGH 7.7
npm

GHSA-pvcr-8mvp-w8qr

Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)

HIGH 8.5
npm

GHSA-xg5g-26x8-cvf4

Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution

HIGH 8.3
npm

GHSA-qw6m-8fw2-2v64

Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution

HIGH 7.7
npm

GHSA-xcx6-4f2g-hhgx

Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLs

UNKNOWN
npm

GHSA-mqhr-6j6h-74p5

Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak

UNKNOWN
npm

GHSA-c8vc-7pv3-g98p

Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)

UNKNOWN
npm

GHSA-ppr4-5f46-j9c6

Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile

HIGH 7.5
npm

GHSA-hr66-5mqr-8mpx

Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint

MEDIUM 4.9
npm

GHSA-fcrw-f7gg-6g9f

Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users

MEDIUM 5.7
npm

GHSA-gh4h-34gr-87r7

Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders

UNKNOWN
npm

GHSA-hp6v-6jw7-gv2f

Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified

HIGH 7.6
npm

GHSA-2xgg-r2wc-c5r2

Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector

CRITICAL 9.6
npm

GHSA-q6x4-v3qx-85qw

Budibase: SQL Injection via `multipleStatements: true`

MEDIUM 4.3
npm

GHSA-4qcj-m5wp-jmf4

Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings

HIGH 8.8
npm

GHSA-j9fc-w3mr-x6mv

Budibase: Privilege escalation via public role assignment API missing app-level authorization

HIGH 7.3
npm

CVE-2026-50132

Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF

HIGH 8.2
npm

CVE-2026-54351

Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Override

CRITICAL 9.4
npm

CVE-2026-50137

Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentials

HIGH 7.4
npm

CVE-2026-50136

Budibase: Unauthenticated S3 signed upload URL generation allows arbitrary writes with stored datasource credentials

CRITICAL 10.0
npm

CVE-2026-54350

Budibase has nonymous NoSQL operator injection via published-app query templates

CRITICAL 9.6
npm

CVE-2026-54352

Budibase has arbitrary file read by workspace-builder via PWA-zip symlink upload

HIGH 8.5
npm

CVE-2026-48153

Budibase: SSRF via OAuth2 token endpoint URL reaches internal hosts and cloud metadata

CRITICAL 9.0
npm

CVE-2026-48150

Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign

UNKNOWN
npm

CVE-2026-48148

Budibase: Unvalidated VectorDB Host Parameter Enables SSRF

HIGH 7.5
npm

CVE-2026-48151

Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schema

HIGH 8.1
npm

CVE-2026-48152

Budibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasource base URL

HIGH 7.7
npm

CVE-2026-48146

Budibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist Protection

HIGH 7.7
npm

CVE-2026-45548

Budibase: SSRF in AI Extract File Automation Step via Missing IP Blacklist Validation

HIGH 8.8
npm

CVE-2026-45717

Budibase: `PUT /api/datasources/:datasourceId` is protected only by `TABLE/READ` permission instead of builder access, allowing any authenticated app user to overwrite datasource connection parameters including host, port, and URL

MEDIUM 6.5
npm

CVE-2026-45719

Budibase: CouchDB Reduce Injection via Unsanitized Calculation Parameter in V1 Views API

HIGH 7.7
npm

CVE-2026-45715

Budibase: SSRF Bypass via HTTP Redirect in REST Datasource Integration

HIGH 8.8
npm

CVE-2026-25044

Budibase: Command Injection in Bash Automation Step

CRITICAL 9.0
npm

CVE-2026-35216

Budibase: Unauthenticated Remote Code Execution via Webhook Trigger and Bash Automation Step

HIGH 8.7
npm

CVE-2026-35214

Budibase: Path traversal in plugin file upload enables arbitrary directory deletion and file write

UNKNOWN
npm

CVE-2026-25041

@budibase/server: Command Injection in PostgreSQL Dump Command

CRITICAL 9.8
npm

GHSA-4g2x-vq5p-5vj6

Budibase affected by VM2 Constructor Escape Vulnerability

Ready to move

Start Securing

Free, no credit card | First findings in minutes