Budibase是英国Budibase开源的一个用于在几分钟内创建内部应用程序、工作流和管理面板的低代码平台。 Budibase 3.38.1之前版本存在代码问题漏洞,该漏洞源于REST数据源集成在HTTP重定向时未重新检查IP黑名单,可能导致认证构建者通过攻击者控制的服务器重定向访问内部服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-46425 | 9.9 CRITICAL | Budibase: SCIM endpoints lack role-based authorization, BASIC users CRUD tenant users |
| CVE-2026-48150 | 9.0 CRITICAL | Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assi |
| CVE-2026-45716 | 8.8 HIGH | Budibase: Builder-to-Admin Privilege Escalation via onboardUsers Endpoint Without SMTP Con |
| CVE-2026-45717 | 8.8 HIGH | Budibase: `PUT /api/datasources/:datasourceId` is protected only by `TABLE/READ` permissio |
| CVE-2026-48153 | 8.5 HIGH | Budibase: SSRF via OAuth2 token endpoint URL reaches internal hosts and cloud metadata |
| CVE-2026-48152 | 8.1 HIGH | Budibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasour |
| CVE-2026-48149 | 8.1 HIGH | Budibase: Stored XSS in Text component: BASIC users execute JS in admin session via Markdo |
| CVE-2026-45548 | 7.7 HIGH | Budibase: SSRF in AI Extract File Automation Step via Missing IP Blacklist Validation |
| CVE-2026-45061 | 7.7 HIGH | Budibase: SSRF via trivial `.tar.gz` substring bypass in Plugin URL upload (`/api/plugin`) |
| CVE-2026-48146 | 7.7 HIGH | Budibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist Protection |
| CVE-2026-46427 | 7.7 HIGH | Budibase: Snowflake private key returned unmasked from datasource API to BASIC users |
| CVE-2026-46426 | 7.6 HIGH | Budibase: Unrestricted Upload of File with Dangerous Type |
| CVE-2026-48151 | 7.5 HIGH | Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of |
| CVE-2026-48147 | 6.5 MEDIUM | Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection |
| CVE-2026-45719 | 6.5 MEDIUM | Budibase: CouchDB Reduce Injection via Unsanitized Calculation Parameter in V1 Views API |
| CVE-2026-45718 | 5.4 MEDIUM | Budibase: Row Action Trigger Bypasses View Row Filter Security Boundary Allowing Action on |
| CVE-2026-46424 | 4.2 MEDIUM | Budibase: Missing Cache Invalidation on Public API Role Unassignment Allows Revoked Users |
| CVE-2026-48128 | Budibase: SSRF via User-Controlled queryId in Automation Execute Query Step | |
| CVE-2026-48148 | Budibase: Unvalidated VectorDB Host Parameter Enables SSRF |
No comments yet