SQL Injection Vulnerability in Budibase Low-Code Platform
CVE-2026-64657
8.4HIGH
What is CVE-2026-64657?
The Budibase low-code platform, up to version 3.39.19, contains a SQL injection vulnerability in its PostgreSQL datasource connector. An authenticated administrator can exploit this weakness by saving or testing the datasource, allowing for the execution of arbitrary SQL commands through the simple query protocol. The vulnerability arises from the interpolation of user-controlled schema configuration fields into a SET search_path statement, where embedded double quotes are not properly escaped. This oversight can lead to significant security risks and potential unauthorized access to the database.
Affected Version(s)
budibase < 3.39.19
