Arbitrary Code Execution Vulnerability in Budibase Low-Code Platform
CVE-2026-45719

6.5MEDIUM

Key Information:

Vendor

Budibase

Status
Vendor
CVE Published:
27 May 2026

What is CVE-2026-45719?

Budibase, an open-source low-code platform, has a vulnerability in its V1 Views API (POST /api/views), where it accepts a calculation parameter without proper validation before using it in a CouchDB reduce function. As a result, users with Builder permissions can inject arbitrary JavaScript code, which would be executed within the CouchDB JavaScript engine when the view is queried. This issue has been addressed in version 3.38.1.

Affected Version(s)

budibase < 3.38.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.