Path Traversal Vulnerability in Budibase by Budibase
CVE-2026-72850

9.4CRITICAL

Key Information:

Vendor

Budibase

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-72850?

Budibase versions prior to 3.40.0 contain a path traversal vulnerability that can be exploited by authenticated builders. Due to improper sanitization of S3 object keys, attackers can craft filenames with traversal sequences that successfully escape the temporary directory during workspace export. This oversight allows for the upload of arbitrary content to any directory writable by the Budibase process, potentially compromising the integrity and confidentiality of the system.

Affected Version(s)

server 0 < 3.40.0

server 3.40.0

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hypnguyen1209
.