PT-2026-83096 · Budibase · Budibase
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Budibase versions prior to 3.41.3
Description
Authenticated admin users can achieve remote code execution by uploading a malicious plugin tarball. The issue occurs because the server uses the
eval() function on plugin JavaScript files without sandboxing within the main Node.js process. This allows attackers to execute arbitrary code and exfiltrate environment variables and credentials with root privileges in default deployments.Recommendations
Update to version 3.41.3 or later.
Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Budibase