Budibase是英国Budibase公司开源的一个用于在几分钟内创建内部应用程序、工作流和管理面板的低代码平台。 Budibase 3.39.0之前版本存在安全漏洞,该漏洞源于对/api/chat-links/:instance/:token/handoff端点缺乏身份验证、用户同意界面及跨站请求伪造保护,可能导致攻击者将外部聊天身份绑定到已认证用户账户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-54350 | 10.0 CRITICAL | Budibase: Anonymous NoSQL operator injection via published-app query templates |
| CVE-2026-54352 | 9.6 CRITICAL | Budibase: Arbitrary file read by workspace-builder via PWA-zip symlink upload |
| CVE-2026-54353 | 8.5 HIGH | Budibase: Potential SSRF DNS rebinding bypass in outbound fetch validation |
| CVE-2026-54351 | 8.2 HIGH | Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution v |
| CVE-2026-50136 | 7.4 HIGH | Budibase: Unauthenticated S3 signed upload URL generation allows arbitrary writes with sto |
| CVE-2026-50137 | Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous ca |
No comments yet