Budibase auth session cookies are set with httpOnly:false — any XSS can lead to full account takeover
Modified: 5/11/2026
package
pkg:npm/%40budibase/backend-core
Budibase auth session cookies are set with httpOnly:false — any XSS can lead to full account takeover
Modified: 5/11/2026
Budibase: Missing Cache Invalidation on Public API Role Unassignment Allows Revoked Users to Retain Privileges for Up to 1 Hour
Modified: 9/10/2026
Budibase: Server-Side Request Forgery via REST Connector with Empty Default Blacklist
Modified: 4/3/2026
Budibase: Authentication Bypass via Unanchored Regex in Public Endpoint Matcher — Unauthenticated Access to Protected Endpoints
Modified: 5/5/2026
@budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation
Modified: 8/12/2026
Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Worker
Modified: 9/10/2026