PT-2026-71907 · Budibase · Budibase
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Budibase versions prior to 3.40.0
Description
Authenticated builders can upload files containing traversal sequences in S3 object keys because the software fails to properly sanitize them. These sequences are preserved during workspace export, allowing attackers to use filenames with
.. segments to escape the temporary directory and write arbitrary content to any path accessible by the Budibase process.Recommendations
Update to version 3.40.0 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Budibase