Security score
32 known advisories in v3.38.1
OpenSSF Scorecard 5.1/10
Weekly downloads
—
Unpacked size
59.0 MB
Dependencies
95
Last publish
4 months ago
Security advisories
- Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connectorhigh
GHSA-2xgg-r2wc-c5r2
- Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentialshigh
GHSA-35c4-rvc8-frhm · fixed in 3.39.0
- Budibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasource base URLhigh
GHSA-3gp5-q4jw-3v94 · fixed in 3.39.0
- Budibase: SSRF via OAuth2 token endpoint URL reaches internal hosts and cloud metadatahigh
GHSA-4q6h-8p4v-67vq · fixed in 3.39.0
- Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklisthigh
GHSA-5fpj-28rv-84r7 · fixed in 3.41.3
- Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assigncritical
GHSA-6xp4-cf37-ppjh · fixed in 3.39.0
- Budibase has nonymous NoSQL operator injection via published-app query templatescritical
GHSA-8qv3-p479-cj62 · fixed in 3.39.12
- Budibase: Account Enumeration via Login Lockout Response Differentialmoderate
GHSA-cr7p-cr3q-h5cm
- Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Usersmoderate
GHSA-fcrw-f7gg-6g9f · fixed in 3.39.25
- Budibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist Protectionhigh
GHSA-g6qx-g4pr-92v7 · fixed in 3.39.0
- Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Buildersmoderate
GHSA-gh4h-34gr-87r7
- Budibase: SSRF via bare fetch() in uploadUrl during AI table generationmoderate
GHSA-hfhx-w8p8-4hc7
- Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verifiedcritical
GHSA-hp6v-6jw7-gv2f
- Budibase: Unauthenticated user information disclosure via public tenant user lookup endpointhigh
GHSA-hr66-5mqr-8mpx
- Budibase: Unauthenticated S3 signed upload URL generation allows arbitrary writes with stored datasource credentialshigh
GHSA-jj36-r9w3-3pfh · fixed in 3.39.2
- Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leakcritical
GHSA-mqhr-6j6h-74p5
- high
- Budibase: SQL Injection via `multipleStatements: true`critical
GHSA-q6x4-v3qx-85qw
- Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schemahigh
GHSA-qhv3-wjg8-6fx6 · fixed in 3.39.0
- Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Executionhigh
GHSA-qw6m-8fw2-2v64
- Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Overridehigh
GHSA-rgvg-3wpc-h44p · fixed in 3.39.9
- Budibase: SSRF via DNS rebinding in the REST datasource integrationhigh
GHSA-v42f-v8xc-j435
- Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRFhigh
GHSA-v7j5-vc4m-723w · fixed in 3.39.0
- Budibase has arbitrary file read by workspace-builder via PWA-zip symlink uploadcritical
GHSA-w7mq-r738-x278 · fixed in 3.39.9
- Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query executionhigh
GHSA-xg5g-26x8-cvf4
OpenSSF ScorecardAug 24, 2026
- Maintained10
- Code-Review6
- Security-Policy10
- CII-Best-Practices0
- Dangerous-Workflow10
- Token-Permissions0
- License9
- Binary-Artifacts6
- Branch-Protection5
- Signed-Releases0
- SAST0
- Fuzzing0
- Packaging10
- Pinned-Dependencies2