PT-2026-71446 · Budibase+1 · @Budibase/Server+1
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Budibase Server versions prior to 3.40.0
Description
NoSQL injection occurs in the MongoDB query execution endpoint when user-supplied parameters are interpolated into JSON query templates without proper sanitization of JSON metacharacters. Attackers with query write permissions can inject JSON structural characters to alter MongoDB queries, allowing them to bypass filters to read, modify, or delete arbitrary documents.
Recommendations
Update Budibase Server to version 3.40.0 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Budibase/Server
Mongodb