Path Traversal Vulnerability in Budibase Low-Code Platform
CVE-2026-30240

9.6CRITICAL

Key Information:

Vendor

Budibase

Status
Vendor
CVE Published:
9 March 2026

What is CVE-2026-30240?

A significant path traversal vulnerability exists in the Budibase low-code platform, specifically in versions 3.31.5 and earlier. This flaw affects the Progressive Web App (PWA) ZIP processing endpoint, allowing authenticated users with builder privileges to access arbitrary files on the server's filesystem. By leveraging an unsanitized input path, attackers can retrieve sensitive files, including environment variable configurations that contain critical information such as JWT secrets, database credentials, and API tokens. This exposure can lead to a total compromise of the platform, as attackers can exfiltrate all cryptographic secrets and service credentials in a single request.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

budibase <= 3.31.5

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.