File Attachment Vulnerability in Budibase Low-Code Platform
CVE-2026-73307

4.9MEDIUM

Key Information:

Vendor

Budibase

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-73307?

Budibase, an open-source low-code platform, was found to have a vulnerability where string attachment values could be fetched without adequate validation. This issue arose in versions before 3.39.4, specifically within the uploadUrl functionality. A builder utilizing the AI table-generation feature could inadvertently expose internal services or cloud metadata endpoints. The resultant responses may be saved as attachments, bypassing crucial fetchWithBlacklist validations, potentially leading to unauthorized data exposure. This vulnerability has been addressed in version 3.39.4.

Affected Version(s)

budibase < 3.39.4

References

CVSS V4

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.