Arbitrary File Read Vulnerability in Budibase by Budibase
CVE-2026-100680
8.6HIGH
What is CVE-2026-100680?
Budibase versions prior to 3.45.0 have a significant security vulnerability due to their failure to disable external JSON reference resolution within the OpenAPI/Swagger import validator. Authenticated builders can exploit this vulnerability by embedding 'file://' references in OpenAPI specifications submitted to the import endpoint. This exploitation allows attackers to read sensitive local files, including environment variables that may contain JWT secrets, API keys, and database credentials, ultimately compromising the security of applications built on Budibase.
Affected Version(s)
server 0 < 3.45.0
server 3.45.0
