CVE-2026-25041

Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.23.22 and earlier, the PostgreSQL integration constructs shell commands using user-controlled configuration values (database name, host, password, etc.) without proper sanitization. The password and other connection parameters are directly interpolated into a shell command. This affects packages/server/src/integrations/postgres.ts.
Configurations

Configuration 1 (hide)

cpe:2.3:a:budibase:budibase:*:*:*:*:*:*:*:*

History

13 Mar 2026, 19:23

Type Values Removed Values Added
References () https://github.com/Budibase/budibase/blob/f34d545602a7c94427bae63312a5ee9bf2aa6c85/packages/server/src/integrations/postgres.ts#L529-L531 - () https://github.com/Budibase/budibase/blob/f34d545602a7c94427bae63312a5ee9bf2aa6c85/packages/server/src/integrations/postgres.ts#L529-L531 - Product
References () https://github.com/Budibase/budibase/commit/9fdbff32fb9e69650ba899a799e13f80d9b09e93 - () https://github.com/Budibase/budibase/commit/9fdbff32fb9e69650ba899a799e13f80d9b09e93 - Patch
References () https://github.com/Budibase/budibase/security/advisories/GHSA-726g-59wr-cj4c - () https://github.com/Budibase/budibase/security/advisories/GHSA-726g-59wr-cj4c - Exploit, Vendor Advisory
CPE cpe:2.3:a:budibase:budibase:*:*:*:*:*:*:*:*
First Time Budibase
Budibase budibase
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2

11 Mar 2026, 13:53

Type Values Removed Values Added
Summary
  • (es) Budibase es una plataforma de bajo código para crear herramientas internas, flujos de trabajo y paneles de administración. En 3.23.22 y anteriores, la integración de PostgreSQL construye comandos de shell utilizando valores de configuración controlados por el usuario (nombre de la base de datos, host, contraseña, etc.) sin una sanitización adecuada. La contraseña y otros parámetros de conexión se interpolan directamente en un comando de shell. Esto afecta a packages/server/src/integrations/postgres.ts.

09 Mar 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-09 20:16

Updated : 2026-03-13 19:23


NVD link : CVE-2026-25041

Mitre link : CVE-2026-25041

CVE.ORG link : CVE-2026-25041


JSON object : View

Products Affected

budibase

  • budibase
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')