GHSA-fc2x-q7pq-fp49HighCVSS 8.1

Budibase versions before 3.45.0 fail to disable external JSON reference resolution in the OpenAPI...

Published
September 26, 2026
Last Modified
September 26, 2026

🔗 CVE IDs covered (1)

📋 Description

Budibase versions before 3.45.0 fail to disable external JSON reference resolution in the OpenAPI/Swagger import validator, allowing authenticated builders to read arbitrary local files. Attackers with builder access can embed file:// references in OpenAPI specifications submitted to the import endpoint to exfiltrate sensitive files including environment variables containing JWT secrets, API keys, and database credentials.

🔗 References (4)