Loading...
Skip to main content
npm (Node.js)

@budibase/server Security Analysis

@budibase/server has 11 known security vulnerabilities in npm (Node.js). Upgrade to version 3.39.12 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.

11 Vulnerabilities

Low Immediate Risk

No actively exploited vulnerabilities detected. Monitor and update in your next maintenance window.

Recommended safe version: 3.39.12

Upgrading to 3.39.12 or later resolves all 11 known vulnerabilities in @budibase/server. Run: npm install @budibase/server@3.39.12

Is @budibase/server in your project?

Check if you're affected and upgrade to 3.39.12 to stay secure.

11
Total
0
Critical
0
High
0
Medium
0
Low

Vulnerabilities

11 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.

CVE / GHSASeverityAffectedFixed In
CVE-2026-54350
Budibase has nonymous NoSQL operator injection via published-app query templates
CRITICAL
All versions3.39.12
CVE-2026-73300
Budibase: SQL Injection via `multipleStatements: true`
CRITICAL
All versionsNo fix available
CVE-2026-54352
Budibase has arbitrary file read by workspace-builder via PWA-zip symlink upload
CRITICAL
All versions3.39.9
CVE-2026-73302
Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified
CRITICAL
All versionsNo fix available
CVE-2026-48150
Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign
CRITICAL
All versions3.39.0
CVE-2026-35216
Budibase: Unauthenticated Remote Code Execution via Webhook Trigger and Bash Automation Step
CRITICAL
All versions3.33.4
CVE-2026-50137
Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentials
HIGH
All versions3.39.0
CVE-2026-73305
Budibase: Privilege escalation via public role assignment API missing app-level authorization
HIGH
All versionsNo fix available
CVE-2026-45717
Budibase: `PUT /api/datasources/:datasourceId` is protected only by `TABLE/READ` permission instead of builder access, allowing any authenticated app user to overwrite datasource connection parameters including host, port, and URL
HIGH
All versions3.38.1
CVE-2026-25044
Budibase: Command Injection in Bash Automation Step
HIGH
All versions3.33.4
CVE-2026-35214
Budibase: Path traversal in plugin file upload enables arbitrary directory deletion and file write
HIGH
All versions3.33.4

About This Data

Vulnerability data for @budibase/server is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.

CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Related npm (Node.js) Packages

Other packages in this ecosystem, ranked by shared vulnerabilities where available.

Check Your Dependencies

Scan your project to check if you're using a vulnerable version of @budibase/server.

Data from OSV DatabaseUpdated daily200K+ vulnerabilities indexed