<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T03:41:25.286481+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-322242</id>
    <title>EUVD-2026-322242</title>
    <updated>2026-10-04T03:41:25.289229+00:00</updated>
    <content>EUVD-2026-322242</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-322242"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48128</id>
    <title>fkie_cve-2026-48128</title>
    <updated>2026-10-04T03:41:25.289260+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Budibase is an open-source low-code platform. Prior to 3.39.0, the executeQuery automation step in Budibase accepts a queryId from automation step inputs and passes it directly to the query execution controller without additional validation. When combined with a REST datasource configured to target internal infrastructure, this creates a server-side request forgery path where automation execution causes the Budibase server to make outbound HTTP requests to attacker-influenced destinations. The automation output then returns the response, potentially exposing internal service data. This vulnerability is fixed in 3.39.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-48128"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6964-pp88-6wp9</id>
    <title>GHSA-6964-pp88-6wp9 — Budibase: SSRF via User-Controlled queryId in Automation Execute Query Step</title>
    <updated>2026-10-04T03:41:25.289293+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: budibase</p>
<p>### Summary</p>
<p>The executeQuery automation step in Budibase accepts a queryId from automation step inputs and passes it directly to the query execution controller without additional validation. When combined with a REST datasource configured to target internal infrastructure, this creates a server-side request forgery path where automation execution causes the Budibase server to make outbound HTTP requests to attacker-influenced destinations. The automation output then returns the response, potentially exposing internal service data.</p>
<p>### Details</p>
<p>Inside the execute query automation step, the queryId value and any additional query parameters from `inputs.query` are assembled into a request context and forwarded to `queryController.executeV2AsAutomation`. The constructed context looks like the following:</p>
<p>```typescript
const ctx: any = buildCtx(appId, emitter, {
  body: {
    parameters: rest,
  },
  params: {
    queryId,
  },
  user: context.user,
})
```</p>
<p>No validation is performed to confirm that the referenced query is appropriate for automation use, that the associated datasource targets an allowlisted destination, or that the supplied parameters do not override security-sensitive fields. The `context.user` value is also forwarded directly from automation context into the request, which may allow caller identity to be influenced by automation binding inputs.</p>
<p>To reach exploitation, an attacker needs builder-level access to the Budibase application. With that access, they c…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6964-pp88-6wp9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1629</id>
    <title>WID-SEC-W-2026-1629 — Budibase: Mehrere Schwachstellen</title>
    <updated>2026-10-04T03:41:25.289357+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Budibase ausnutzen, um Administratorrechte zu erlangen, Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren oder vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1629"/>
  </entry>
</feed>
