CVE-2026-50137
HIGH SEVERITYVulnerability Description
Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentials
Vulnerability Details
Published Date
Last Modified
Source
GitHub
Vendor
npm
Product
@budibase/server
Discussion (0)
Add Comment
No comments yet. Be the first!