PT-2026-99351 · Budibase · Budibase

·

CVE-2026-100680

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Budibase versions prior to 3.45.0
Description Authenticated builders can read arbitrary local files because the OpenAPI/Swagger import validator fails to disable external JSON reference resolution. By embedding file:// references within OpenAPI specifications submitted to the import endpoint, an attacker with builder access can exfiltrate sensitive files, such as environment variables containing JWT secrets, API keys, and database credentials.
Recommendations Update to version 3.45.0 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100680
GHSA-8XR5-PGGF-26JQ

Affected Products

Budibase