Vulnerability Description
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.23.22 and earlier, the PostgreSQL integration constructs shell commands using user-controlled configuration values (database name, host, password, etc.) without proper sanitization. The password and other connection parameters are directly interpolated into a shell command. This affects packages/server/src/integrations/postgres.ts.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Budibase | Budibase | <= 3.23.22 |
Related Weaknesses (CWE)
References
- https://github.com/Budibase/budibase/blob/f34d545602a7c94427bae63312a5ee9bf2aa6cProduct
- https://github.com/Budibase/budibase/commit/9fdbff32fb9e69650ba899a799e13f80d9b0Patch
- https://github.com/Budibase/budibase/security/advisories/GHSA-726g-59wr-cj4cExploitVendor Advisory
FAQ
What is CVE-2026-25041?
CVE-2026-25041 is a vulnerability with a CVSS score of 7.2 (HIGH). Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.23.22 and earlier, the PostgreSQL integration constructs shell commands using user-controlled configurati...
How severe is CVE-2026-25041?
CVE-2026-25041 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-25041?
Check the references section above for vendor advisories and patch information. Affected products include: Budibase Budibase.