Path Traversal Vulnerability in Budibase Low-Code Platform
CVE-2026-30240
What is CVE-2026-30240?
A significant path traversal vulnerability exists in the Budibase low-code platform, specifically in versions 3.31.5 and earlier. This flaw affects the Progressive Web App (PWA) ZIP processing endpoint, allowing authenticated users with builder privileges to access arbitrary files on the server's filesystem. By leveraging an unsanitized input path, attackers can retrieve sensitive files, including environment variable configurations that contain critical information such as JWT secrets, database credentials, and API tokens. This exposure can lead to a total compromise of the platform, as attackers can exfiltrate all cryptographic secrets and service credentials in a single request.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
budibase <= 3.31.5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
