VDB
Sign up

package

npm/@budibase/server

pkg:npm/%40budibase/server

CRITICAL9.4npm
GHSA-35c4-rvc8-frhm· CVE-2026-50137

Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentials

Modified: 7/21/2026

HIGH8.8npm
GHSA-44m2-crh7-f4q2· CVE-2026-45717

Budibase: `PUT /api/datasources/:datasourceId` is protected only by `TABLE/READ` permission instead of builder access, allowing any authenticated app user to overwrite datasource connection parameters including host, port, and URL

Modified: 9/10/2026

CRITICAL9.8npm
GHSA-4g2x-vq5p-5vj6

Budibase affected by VM2 Constructor Escape Vulnerability

Modified: 8/15/2024

MEDIUM4.3npm
GHSA-4qcj-m5wp-jmf4· CVE-2026-73301

Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings

Modified: 8/12/2026

HIGHnpm
GHSA-c8vc-7pv3-g98p· CVE-2026-73303

Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)

Modified: 8/12/2026

HIGH7.4npm
GHSA-jj36-r9w3-3pfh· CVE-2026-50136

Budibase: Unauthenticated S3 signed upload URL generation allows arbitrary writes with stored datasource credentials

Modified: 7/17/2026

HIGH7.1npm
GHSA-pmpg-2mxq-6xwr· CVE-2026-73617

Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete

Modified: 8/14/2026

HIGH7.5npm
GHSA-qhv3-wjg8-6fx6· CVE-2026-48151

Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schema

Modified: 9/10/2026

HIGH7.7npm
GHSA-xcx6-4f2g-hhgx· CVE-2026-72859

Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLs

Modified: 8/15/2026