CyberRota Analysis
AI-GeneratedBudibase versions prior to 3.45.0 are vulnerable due to inadequate restrictions on external JSON reference resolution in the OpenAPI/Swagger import validator, enabling authenticated builders to access arbitrary local files. This flaw allows attackers with builder access to exfiltrate sensitive information such as JWT secrets, API keys, and database credentials by embedding file:// references in submitted OpenAPI specifications. Organizations using affected versions should prioritize patching to mitigate the risk of sensitive data exposure.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Budibase versions before 3.45.0 fail to disable external JSON reference resolution in the OpenAPI/Swagger import validator, allowing authenticated builders to read arbitrary local files. Attackers with builder access can embed file:// references in OpenAPI specifications submitted to the import endpoint to exfiltrate sensitive files including environment variables containing JWT secrets, API keys, and database credentials.