CVE-2026-25737

Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.24.0 and earlier, an arbitrary file upload vulnerability exists even though file extension restrictions are configured. The restriction is enforced only at the UI level. An attacker can bypass these restrictions and upload malicious files.
Configurations

No configuration.

History

09 Mar 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-09 21:16

Updated : 2026-03-09 21:16


NVD link : CVE-2026-25737

Mitre link : CVE-2026-25737

CVE.ORG link : CVE-2026-25737


JSON object : View

Products Affected

No product.

CWE
CWE-602

Client-Side Enforcement of Server-Side Security