Budibase 3.45.0 之前的版本未能在 OpenAPI/Swagger 导入验证器中禁用外部 JSON 引用解析功能,使得拥有验证权限的构建者(builder)能够读取任意本地文件。具有构建者权限的攻击者可以在提交到导入端点的 OpenAPI 规范中嵌入 引用,从而外泄敏感文件,包括包含 JWT 密钥、API 密钥和数据库凭据的环境变量。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100682 | 8.8 HIGH | Budibase Server before 3.45.0 Arbitrary File Write via ZIP Symlink |
| CVE-2026-100686 | 8.1 HIGH | Budibase before 3.45.0 Cross-Workspace Privilege Escalation via POST /api/global/groups/:g |
| CVE-2026-100684 | 8.1 HIGH | Budibase Server 3.41.0 before 3.45.0 Authentication Bypass via OIDC |
| CVE-2026-100683 | 8.0 HIGH | Budibase before 3.45.0 SQL Injection via column-rename DDL |
| CVE-2026-100685 | 7.7 HIGH | Budibase before 3.45.0 Information Disclosure via Chat Links |
| CVE-2026-100688 | 6.5 MEDIUM | Budibase server before 3.45.0 Cross-Tenant Information Disclosure |
| CVE-2026-100687 | 5.5 MEDIUM | Budibase Server before 3.45.0 Credential Exposure via External Table Broadcast |
| CVE-2026-100681 | 5.4 MEDIUM | Budibase before 3.45.0 SSRF and OAuth Token Exfiltration via Teams Webhook |
No comments yet