Back to CVE List

CVE-2026-50137

HIGH SEVERITY

Vulnerability Description

Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentials

Vulnerability Details

Published Date
Last Modified
Source
GitHub
Vendor
npm
Product
@budibase/server

External References

Discussion (0)

Add Comment

No comments yet. Be the first!