Arbitrary Code Execution Vulnerability in Budibase Low-Code Platform
CVE-2026-45719
6.5MEDIUM
What is CVE-2026-45719?
Budibase, an open-source low-code platform, has a vulnerability in its V1 Views API (POST /api/views), where it accepts a calculation parameter without proper validation before using it in a CouchDB reduce function. As a result, users with Builder permissions can inject arbitrary JavaScript code, which would be executed within the CouchDB JavaScript engine when the view is queried. This issue has been addressed in version 3.38.1.
Affected Version(s)
budibase < 3.38.1
