Mass Assignment Vulnerability in Budibase Low-Code Platform
CVE-2026-54351
8.2HIGH
What is CVE-2026-54351?
Budibase, an open-source low-code platform, is susceptible to a mass assignment vulnerability due to a publicly accessible webhook trigger endpoint. This flaw allows an attacker to manipulate automation execution parameters by overwriting the internal appId property through crafted POST requests. Consequently, when webhook automation is processed asynchronously, the attacker can execute arbitrary actions within the victim's workspace, leading to unauthorized read/write access to the database. This vulnerability has been addressed in version 3.39.9.
Affected Version(s)
budibase < 3.39.9
