Arbitrary Command Execution Vulnerability in Budibase Low-Code Platform
CVE-2026-25044

8.7HIGH

Key Information:

Vendor

Budibase

Status
Vendor
CVE Published:
3 April 2026

What is CVE-2026-25044?

Budibase, an open-source low-code platform, contains a vulnerability where the bash automation step can execute user-provided commands without adequate input sanitization or validation. Specifically, prior to version 3.33.4, an issue arises in the processing of user input through the processStringSync function, which allows for template interpolation. This security flaw potentially enables attackers to perform arbitrary command execution, posing significant risks to the integrity of the system. A patch has been released in version 3.33.4 to address this vulnerability.

Affected Version(s)

budibase < 3.33.4

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.