@budibase/backend-core
npm3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @budibase/backend-corepage 1 of 1
- CVE-2026-31818CRITICALCVSS 9.6EG 9.6✓ Fixed in 3.33.42026-04-03
Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST datasource connector. The platform's SSRF protection mechanism (IP blacklist) is rendered c…
- CVE-2026-41428CRITICALCVSS 9.1EG 9.12026-04-24
Budibase is an open-source low-code platform. Prior to 3.35.4, the authenticated middleware uses unanchored regular expressions to match public (no-auth) endpoint patterns against ctx.request.url. Since ctx.request.url in Koa includes the …
- CVE-2026-42239HIGHCVSS 8.1EG 8.1✓ Fixed in 3.35.102026-05-07
Budibase is an open-source low-code platform. Prior to version 3.35.10, the budibase:auth cookie containing the JWT session token is set with httpOnly: false at packages/backend-core/src/utils/utils.ts:218. JavaScript can read this cookie …
Check whether @budibase/backend-core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @budibase/backend-core CVEs against the assets you own.
Start Free Scan →