PT-2026-30171 · Budibase · Budibase

Omkarparth

·

Published

2026-04-03

·

Updated

2026-04-10

·

CVE-2026-25044

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Budibase versions prior to 3.33.4
Description Budibase, an open-source low-code platform, prior to version 3.33.4, allows arbitrary command execution through the bash automation step. This occurs because user-provided commands are executed using execSync without sufficient sanitization or validation. User input is processed via processStringSync, which enables template interpolation, potentially leading to the execution of unintended commands.
Recommendations Update Budibase to version 3.33.4 or later.

Fix

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-25044
GHSA-GJW9-34GF-RP6M

Affected Products

Budibase