PT-2026-83096 · Budibase · Budibase

·

CVE-2026-82244

·

Published

2026-08-28

·

Updated

2026-08-28

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Budibase versions prior to 3.41.3
Description Authenticated admin users can achieve remote code execution by uploading a malicious plugin tarball. The issue occurs because the server uses the eval() function on plugin JavaScript files without sandboxing within the main Node.js process. This allows attackers to execute arbitrary code and exfiltrate environment variables and credentials with root privileges in default deployments.
Recommendations Update to version 3.41.3 or later.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82244
GHSA-GWR2-PGG3-P7XP

Affected Products

Budibase