Path Traversal Vulnerability in Budibase Low-Code Platform
CVE-2026-35214

8.7HIGH

Key Information:

Vendor

Budibase

Status
Vendor
CVE Published:
3 April 2026

What is CVE-2026-35214?

Budibase, an open-source low-code platform, has a vulnerability in its plugin file upload endpoint. Before version 3.33.4, it improperly handles user-supplied filenames, allowing an attacker with Global Builder privileges to exploit path traversal sequences. By crafting a multipart upload request containing '../', the attacker can delete arbitrary directories and write files to any accessible filesystem path on the Node.js process. This critical flaw has been remedied in version 3.33.4, and it is crucial for users to update to this version to mitigate the risk.

Affected Version(s)

budibase < 3.33.4

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.