Security: Budibase/budibase
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/deleteGHSA-pmpg-2mxq-6xwr published
Jul 22, 2026 by mjashanksHigh -
Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assignGHSA-6xp4-cf37-ppjh published
May 21, 2026 by mjashanksCritical -
Snowflake private key returned unmasked from datasource API to BASIC usersGHSA-qv26-4hvj-m7fv published
May 14, 2026 by mjashanksHigh -
SSRF via OAuth2 token endpoint URL reaches internal hosts and cloud metadataGHSA-4q6h-8p4v-67vq published
May 21, 2026 by mjashanksHigh -
Authentication Bypass via Unanchored Regex in Public Endpoint Matcher — Unauthenticated Access to Protected EndpointsGHSA-8783-3wgf-jggf published
Apr 16, 2026 by mjashanksCritical -
Auth session cookie set with httpOnly:false — any XSS leads to full account takeoverGHSA-4f9j-vr4p-642r published
Apr 21, 2026 by mjashanksHigh -
Missing Cache Invalidation on Public API Role Unassignment Allows Revoked Users to Retain Privileges for Up to 1 HourGHSA-6vp2-6r7m-2jvx published
May 14, 2026 by mjashanksModerate -
SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role UsersGHSA-fcrw-f7gg-6g9f published
Jul 22, 2026 by mjashanksModerate -
Account Enumeration via Login Lockout Response Differential in BudibaseGHSA-cr7p-cr3q-h5cm published
Jul 22, 2026 by mjashanksModerate