Arbitrary Command Execution Vulnerability in Budibase Low-Code Platform
CVE-2026-25044
8.7HIGH
What is CVE-2026-25044?
Budibase, an open-source low-code platform, contains a vulnerability where the bash automation step can execute user-provided commands without adequate input sanitization or validation. Specifically, prior to version 3.33.4, an issue arises in the processing of user input through the processStringSync function, which allows for template interpolation. This security flaw potentially enables attackers to perform arbitrary command execution, posing significant risks to the integrity of the system. A patch has been released in version 3.33.4 to address this vulnerability.
Affected Version(s)
budibase < 3.33.4
