Vulnerability in Budibase Open-Source Low-Code Platform Exposes Filesystem Information
CVE-2026-73409
5.1MEDIUM
What is CVE-2026-73409?
Budibase, a popular low-code development platform, faced a security vulnerability in its server architecture. Prior to version 3.40.1, the platform inadequately handled user-controlled inputs, allowing builders to submit absolute server paths via an API endpoint. This posed a risk by enabling potential attackers to discern readable files on the server, creating a filesystem existence and readability oracle. This vulnerability has been addressed and mitigated in version 3.40.1 to enhance the security posture of Budibase Cloud.
Affected Version(s)
budibase < 3.40.1
