PT-2026-30171 · Budibase · Budibase
Omkarparth
·
Published
2026-04-03
·
Updated
2026-04-10
·
CVE-2026-25044
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Budibase versions prior to 3.33.4
Description
Budibase, an open-source low-code platform, prior to version 3.33.4, allows arbitrary command execution through the bash automation step. This occurs because user-provided commands are executed using
execSync without sufficient sanitization or validation. User input is processed via processStringSync, which enables template interpolation, potentially leading to the execution of unintended commands.Recommendations
Update Budibase to version 3.33.4 or later.
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Budibase