CyberRota Analysis
AI-GeneratedBudibase versions prior to 3.40.0 are vulnerable due to improper sanitization of S3 object keys, enabling authenticated users to exploit directory traversal sequences. This flaw allows attackers to upload files that can overwrite arbitrary paths writable by the Budibase process, potentially leading to unauthorized data exposure or system compromise. Organizations using Budibase should prioritize patching to mitigate this critical risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are preserved during export. Attackers can craft filenames containing .. segments that escape the temporary directory during workspace export, writing arbitrary content to any path writable by the Budibase process.