PT-2026-99353 · Budibase · @Budibase/Server
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Budibase Server versions prior to 3.45.0
Description
An arbitrary file write issue exists in the PWA icon upload endpoint. The system extracts user-supplied ZIP archives without proper symlink validation. Users with the BUILDER role can create a malicious ZIP file containing leaf symlink entries followed by duplicate file entries to write arbitrary files as root, which can lead to remote code execution.
Recommendations
Update Budibase Server to version 3.45.0 or later.
Exploit
Fix
RCE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Budibase/Server