Budibase是英国Budibase公司开源的一个低代码应用开发平台。 Budibase 3.41.3之前版本存在授权问题漏洞,该漏洞源于对POST /api/attachments/:datasourceId/url接口的访问控制不当,允许已认证的BASIC角色用户提供攻击者控制的bucket和key值,获取基于存储的S3数据源凭据的signedUrl和publicUrl值。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-73410 | 8.5 HIGH | Budibase: SSRF via DNS rebinding in the REST datasource integration |
| CVE-2026-64657 | 8.4 HIGH | Budibase: Database Connector SQL Injections in PostgreSQL, MS SQL, and MySQL |
| CVE-2026-35219 | 7.1 HIGH | Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP Blackl |
No comments yet