PT-2026-30193 · Budibase · Budibase

Da7Om85

·

Published

2026-04-03

·

Updated

2026-04-04

·

CVE-2026-35218

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Budibase versions prior to 3.32.5
Description Budibase, an open-source low-code platform, had a critical issue in its Builder Command Palette. Before version 3.32.5, entity names (tables, views, queries, automations) were rendered using Svelte's {@html} directive without proper sanitization. An authenticated user with Builder access could create an entity with a malicious HTML payload (e.g., ) in its name. When another Builder-role user opened the Command Palette (Ctrl+K), this payload would execute in their browser, potentially stealing their session cookie and allowing for full account takeover.
Recommendations Update Budibase to version 3.32.5 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-35218

Affected Products

Budibase