PT-2026-24108 · Budibase · Budibase

Rudrabrahmbhatt

·

Publicado

2026-03-09

·

Atualizado

2026-03-09

·

CVE-2026-25737

CVSS v3.1

9.0

Crítica

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Budibase versions 3.24.0 and earlier
Description Budibase is a low code platform used for creating internal tools, workflows, and admin panels. An arbitrary file upload issue exists because file extension restrictions are only enforced at the user interface level. This allows an attacker to bypass these restrictions and upload malicious files.
Recommendations Versions prior to 3.24.0 should be updated.

Exploit

Correção

XSS

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-25737
GHSA-2HFR-343J-863R

Produtos afetados

Budibase