Budibase · Budibase · CVE-2026-100680
**Name of the Vulnerable Software and Affected Versions**
Budibase versions prior to 3.45.0
**Description**
Authenticated builders can read arbitrary local files because the OpenAPI/Swagger import validator fails to disable external JSON reference resolution. By embedding `file://` references within OpenAPI specifications submitted to the import endpoint, an attacker with builder access can exfiltrate sensitive files, such as environment variables containing JWT secrets, API keys, and database credentials.
**Recommendations**
Update to version 3.45.0 or later.