Path Traversal Vulnerability in Budibase by Budibase
CVE-2026-72850
9.4CRITICAL
What is CVE-2026-72850?
Budibase versions prior to 3.40.0 contain a path traversal vulnerability that can be exploited by authenticated builders. Due to improper sanitization of S3 object keys, attackers can craft filenames with traversal sequences that successfully escape the temporary directory during workspace export. This oversight allows for the upload of arbitrary content to any directory writable by the Budibase process, potentially compromising the integrity and confidentiality of the system.
Affected Version(s)
server 0 < 3.40.0
server 3.40.0
