PT-2026-71445 · Budibase+1 · Budibase+1
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Budibase versions prior to 3.40.0
Description
A NoSQL injection issue exists in the MongoDB datasource integration. The problem occurs because user-supplied parameters are processed using handlebars with
noEscaping: true and are parsed without operator filtering. This allows attackers to inject MongoDB operators through query parameters to bypass per-user access controls, read arbitrary documents, execute JavaScript via $where operators, or modify collections through update and delete operations.Recommendations
Update Budibase to version 3.40.0 or later.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Budibase
Mongodb