SQL Injection Vulnerability in Budibase Low-Code Platform
CVE-2026-73300
9.6CRITICAL
What is CVE-2026-73300?
The Budibase low-code platform is susceptible to SQL injection due to its MySQL integration component, which is configured to allow multiple SQL statements in a single query. This configuration permits attackers to manipulate user inputs and execute arbitrary SQL commands, which can lead to a complete compromise of the underlying database. A security fix was implemented in version 3.40.0, ensuring that SQL injection risks are mitigated.
Affected Version(s)
budibase < 3.40.0
