Budibase 3.41.3 之前的版本在插件处理逻辑中存在远程代码执行漏洞。经过身份验证的管理员用户可以通过上传恶意的插件压缩包(tarball)来执行任意代码。由于服务器在主 Node.js 进程中直接对插件的 JavaScript 文件调用 且未进行沙箱隔离,在默认部署配置下,攻击者能够以 root 权限窃取环境变量和凭据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82240 | 8.1 HIGH | Budibase before 3.41.3 Privilege Escalation via User Update API |
| CVE-2026-82245 | 8.1 HIGH | Budibase before 3.41.3 Missing Authorization License Management |
| CVE-2026-82239 | 8.1 HIGH | Budibase before 3.41.3 Authorization Bypass via datasources/query |
| CVE-2026-82242 | 7.7 HIGH | Budibase before 3.41.3 Cross-Application Resource Injection via Missing Authorization |
| CVE-2026-82243 | 7.6 HIGH | Budibase Server before 3.41.3 SSRF with Credential Leakage |
| CVE-2026-82246 | 7.1 HIGH | Budibase Server before 3.41.3 SSRF via Query Import |
| CVE-2026-82241 | 7.1 HIGH | Budibase backend-core SSRF via incomplete default blacklist |
No comments yet