← Terug naar overzicht

Budibase versions prior to 3.41.3 are affected by a remote code execution vulnerability in the plugin handling mechanism. Authenticated admin users can exploit this flaw by uploading a malicious plugin tarball containing arbitrary JavaScript. The server executes these files using eval() without any sandboxing, running directly in the main Node.js process. This allows attackers to execute arbitrary code with root privileges in default deployments. The vulnerability enables exfiltration of sensitive environment variables and credentials. The issue has been addressed in Budibase version 3.41.3. Given the ease of exploitation by authenticated admins and the potential for full system compromise, this is rated as high severity. Organizations running self-hosted Budibase instances are particularly at risk.

Affected products

  • Budibase < 3.41.3

Related CVE's

  • CVE-2026-82244

Categories

  • Data Breach & Exfiltration
  • Enterprise Applications
  • Web Technologies
  • Zero-Day Vulnerabilities