Path Traversal Vulnerability in Budibase Low-Code Platform
CVE-2026-30240
9.6CRITICAL
What is CVE-2026-30240?
A significant path traversal vulnerability exists in the Budibase low-code platform, specifically in versions 3.31.5 and earlier. This flaw affects the Progressive Web App (PWA) ZIP processing endpoint, allowing authenticated users with builder privileges to access arbitrary files on the server's filesystem. By leveraging an unsanitized input path, attackers can retrieve sensitive files, including environment variable configurations that contain critical information such as JWT secrets, database credentials, and API tokens. This exposure can lead to a total compromise of the platform, as attackers can exfiltrate all cryptographic secrets and service credentials in a single request.
Affected Version(s)
budibase <= 3.31.5
