Security: Budibase/budibase
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Oracle datasource connector is still vulnerable to identifier SQL injection — incomplete fix of GHSA-qqf5-x7mj-v43pGHSA-xj29-x47g-9w2c published
Jul 22, 2026 by mjashanksHigh -
OIDC SSO account takeover: incoming identity linked by email without checking email_verifiedGHSA-hp6v-6jw7-gv2f published
Jul 22, 2026 by mjashanksCritical -
DNS rebinding SSRF bypasses remain in OpenAPI import and REST query executionGHSA-xg5g-26x8-cvf4 published
Jul 22, 2026 by mjashanksHigh -
Any authenticated user (incl. BASIC) can change the account-holder/admin emailGHSA-j82g-67x3-xcwh published
Jul 22, 2026 by mjashanksHigh -
PostgreSQL SET search_path SQL Injection in Database ConnectorGHSA-qqf5-x7mj-v43p published
Jun 18, 2026 by mjashanksHigh -
Datasource secrets stored in STRING typed fields (MongoDB connection string, Firebase private key) are returned unredacted by the datasource read APIGHSA-6mpp-gfg5-x2vv published
Jul 22, 2026 by mjashanksHigh -
Unauthenticated user information disclosure via public tenant user lookup endpointGHSA-hr66-5mqr-8mpx published
Jul 22, 2026 by mjashanksHigh -
S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLsGHSA-xcx6-4f2g-hhgx published
Jul 22, 2026 by mjashanksHigh -
Potential SSRF DNS rebinding bypass in outbound fetch validationGHSA-gfq7-5x4g-3xhf published
Jun 4, 2026 by mjashanksHigh -
SSRF via bare fetch() in uploadUrl during AI table generationGHSA-hfhx-w8p8-4hc7 published
Jul 22, 2026 by mjashanksModerate