PT-2026-71908 · Budibase+1 · Budibase+1
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Budibase versions prior to 3.40.0
Description
An unauthenticated SQL injection exists in webhook-triggered automations that utilize
EXECUTE QUERY steps. An attacker can send a POST request containing malicious JSON to the webhook trigger endpoint to inject SQL payloads. These payloads execute using the database credentials configured by the builder, which may allow for data exfiltration, modification, and the establishment of persistence within connected datasources, such as Snowflake.Recommendations
Update Budibase to version 3.40.0 or later.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Budibase
Snowflake