PT-2026-30193 · Budibase · Budibase
Da7Om85
·
Published
2026-04-03
·
Updated
2026-04-04
·
CVE-2026-35218
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Budibase versions prior to 3.32.5
Description
Budibase, an open-source low-code platform, had a critical issue in its Builder Command Palette. Before version 3.32.5, entity names (tables, views, queries, automations) were rendered using Svelte's {@html} directive without proper sanitization. An authenticated user with Builder access could create an entity with a malicious HTML payload (e.g.,
) in its name. When another Builder-role user opened the Command Palette (Ctrl+K), this payload would execute in their browser, potentially stealing their session cookie and allowing for full account takeover.
Recommendations
Update Budibase to version 3.32.5 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Budibase