CyberRota Analysis
AI-GeneratedBudibase Server versions prior to 3.45.0 are vulnerable to an arbitrary file write flaw in the PWA icon upload endpoint, allowing attackers with a BUILDER role to exploit improperly validated symlink entries in user-supplied ZIP archives. This vulnerability can lead to remote code execution by enabling the writing of arbitrary files as root. Organizations using Budibase Server should prioritize patching to mitigate the risk of potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon upload endpoint that extracts user-supplied ZIP archives without proper symlink validation. Attackers with BUILDER role can craft a malicious ZIP with leaf symlink entries followed by duplicate file entries to write arbitrary files as root, enabling remote code execution.