PT-2026-30191 · Budibase · Budibase

Bugbunny-Research

·

Published

2026-04-03

·

Updated

2026-04-04

·

CVE-2026-35214

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Budibase versions prior to 3.33.4
Description Budibase is an open-source low-code platform. The plugin file upload endpoint, ''/api/plugin/upload'', passes user-supplied filenames directly to the createTempFolder() function without sanitizing path traversal sequences. An attacker with Global Builder privileges can craft a multipart upload with a filename containing '../' to delete arbitrary directories using rmSync and write arbitrary files via tarball extraction to any filesystem path the Node.js process can access.
Recommendations Update to version 3.33.4 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35214
GHSA-2WFH-RCWF-WH23

Affected Products

Budibase