PT-2026-30193 · Budibase · Budibase

·

CVE-2026-35218

·

Published

2026-04-03

·

Updated

2026-04-04

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Budibase versions prior to 3.32.5
Description Budibase, an open-source low-code platform, had a critical issue in its Builder Command Palette. Before version 3.32.5, entity names (tables, views, queries, automations) were rendered using Svelte's {@html} directive without proper sanitization. An authenticated user with Builder access could create an entity with a malicious HTML payload (e.g., ) in its name. When another Builder-role user opened the Command Palette (Ctrl+K), this payload would execute in their browser, potentially stealing their session cookie and allowing for full account takeover.
Recommendations Update Budibase to version 3.32.5 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35218
GHSA-GP5X-2V54-V2Q5

Affected Products

Budibase