File Exposure Vulnerability in Budibase Low-Code Platform
CVE-2026-54352

9.6CRITICAL

Key Information:

Vendor

Budibase

Status
Vendor
CVE Published:
26 June 2026

What is CVE-2026-54352?

The Budibase low-code platform contains a file exposure vulnerability where an attacker could exploit the way uploaded icon files are handled. The platform's API endpoint for processing ZIP files permits the extraction of files that may contain symbolic links. This security flaw allows an unauthorized builder to access any file that the server process can read, including sensitive data, due to inadequate validation of file paths. The issue has been addressed in version 3.39.9, and it is crucial for users to update to this version to mitigate potential risks.

Affected Version(s)

budibase < 3.39.9

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.