@budibase/server Security Analysis
@budibase/server has 11 known security vulnerabilities in npm (Node.js). Upgrade to version 3.39.12 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.
Low Immediate Risk
No actively exploited vulnerabilities detected. Monitor and update in your next maintenance window.
Recommended safe version: 3.39.12
Upgrading to 3.39.12 or later resolves all 11 known vulnerabilities in @budibase/server. Run: npm install @budibase/server@3.39.12
Is @budibase/server in your project?
Check if you're affected and upgrade to 3.39.12 to stay secure.
Vulnerabilities
11 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.
| CVE / GHSA | Severity | Affected | Fixed In |
|---|---|---|---|
| CVE-2026-54350 Budibase has nonymous NoSQL operator injection via published-app query templates | CRITICAL | All versions | 3.39.12 |
| CVE-2026-73300 Budibase: SQL Injection via `multipleStatements: true` | CRITICAL | All versions | No fix available |
| CVE-2026-54352 Budibase has arbitrary file read by workspace-builder via PWA-zip symlink upload | CRITICAL | All versions | 3.39.9 |
| CVE-2026-73302 Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified | CRITICAL | All versions | No fix available |
| CVE-2026-48150 Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign | CRITICAL | All versions | 3.39.0 |
| CVE-2026-35216 Budibase: Unauthenticated Remote Code Execution via Webhook Trigger and Bash Automation Step | CRITICAL | All versions | 3.33.4 |
| CVE-2026-50137 Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentials | HIGH | All versions | 3.39.0 |
| CVE-2026-73305 Budibase: Privilege escalation via public role assignment API missing app-level authorization | HIGH | All versions | No fix available |
| CVE-2026-45717 Budibase: `PUT /api/datasources/:datasourceId` is protected only by `TABLE/READ` permission instead of builder access, allowing any authenticated app user to overwrite datasource connection parameters including host, port, and URL | HIGH | All versions | 3.38.1 |
| CVE-2026-25044 Budibase: Command Injection in Bash Automation Step | HIGH | All versions | 3.33.4 |
| CVE-2026-35214 Budibase: Path traversal in plugin file upload enables arbitrary directory deletion and file write | HIGH | All versions | 3.33.4 |
About This Data
Vulnerability data for @budibase/server is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.
CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Related npm (Node.js) Packages
Other packages in this ecosystem, ranked by shared vulnerabilities where available.
Check Your Dependencies
Scan your project to check if you're using a vulnerable version of @budibase/server.