CVE Tools

@budibase/server

20 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for @budibase/server, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

@budibase/server CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
@budibase/server CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-0719
2026-080
2026-090

Latest CVEs

The 15 most recently published vulnerabilities affecting @budibase/server.

  1. GHSA-hfhx-w8p8-4hc7Budibase: SSRF via bare fetch() in uploadUrl during AI table generation—
  2. GHSA-v42f-v8xc-j435Budibase: SSRF via DNS rebinding in the REST datasource integration—
  3. GHSA-pmpg-2mxq-6xwr Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete—
  4. GHSA-cr7p-cr3q-h5cm Budibase: Account Enumeration via Login Lockout Response Differential—
  5. GHSA-pvcr-8mvp-w8qr Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)—
  6. GHSA-2xgg-r2wc-c5r2Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector—
  7. GHSA-qw6m-8fw2-2v64 Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution—
  8. GHSA-gh4h-34gr-87r7 Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders—
  9. GHSA-hr66-5mqr-8mpx Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint—
  10. GHSA-mqhr-6j6h-74p5 Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak —
  11. GHSA-hp6v-6jw7-gv2f Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified—
  12. GHSA-xg5g-26x8-cvf4 Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution—
  13. GHSA-xcx6-4f2g-hhgx Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLs—
  14. GHSA-ppr4-5f46-j9c6 Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile—
  15. GHSA-q6x4-v3qx-85qw Budibase: SQL Injection via `multipleStatements: true`—

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store