<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T21:07:44.093070+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-322422</id>
    <title>EUVD-2026-322422</title>
    <updated>2026-10-03T21:07:44.440209+00:00</updated>
    <content>EUVD-2026-322422</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-322422"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48151</id>
    <title>fkie_cve-2026-48151</title>
    <updated>2026-10-03T21:07:44.440255+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Budibase is an open-source low-code platform. Prior to 3.39.0, the webhook schema-building endpoint is registered under builderRoutes, but the generic authorization middleware skips authorization for all paths matching /api/webhooks/schema. As a result, an unauthenticated caller can update the body schema for a known webhook and mutate the corresponding automation trigger output schema. This vulnerability is fixed in 3.39.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-48151"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qhv3-wjg8-6fx6</id>
    <title>GHSA-qhv3-wjg8-6fx6 — Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schema</title>
    <updated>2026-10-03T21:07:44.440322+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @budibase/server</p>
<p>The webhook schema-building endpoint is registered under `builderRoutes`, but the generic authorization middleware skips authorization for all paths matching `/api/webhooks/schema`. As a result, an unauthenticated caller can update the body schema for a known webhook and mutate the corresponding automation trigger output schema.</p>
<p>### Details</p>
<p>The route appears to be builder-only:</p>
<p>- `packages/server/src/api/routes/webhook.ts:5-9`</p>
<p>```ts
5:builderRoutes
6:  .get("/api/webhooks", controller.fetch)
7:  .put("/api/webhooks", webhookValidator(), controller.save)
8:  .delete("/api/webhooks/:id/:rev", controller.destroy)
9:  .post("/api/webhooks/schema/:instance/:id", controller.buildSchema)
```</p>
<p>However, webhook endpoint detection explicitly includes `schema`:</p>
<p>- `packages/server/src/middleware/utils.ts:3-9`</p>
<p>```ts
3:const WEBHOOK_ENDPOINTS = new RegExp(
4:  "^/api/webhooks/(trigger|schema|discord|ms-teams|slack)(/|$)"
5:)
6:
7:export function isWebhookEndpoint(ctx: UserCtx): boolean {
8:  const path = ctx.path || ctx.request.url.split("?")[0]
9:  return WEBHOOK_ENDPOINTS.test(path)
```</p>
<p>The authorization middleware bypasses all webhook endpoints before checking `ctx.user` or permissions:</p>
<p>- `packages/server/src/middleware/authorized.ts:90-99`</p>
<p>```ts
90:  ) =&gt;
91:  async (ctx: UserCtx, next: any) =&gt; {
92:    // webhooks don't need authentication, each webhook unique
93:    // also internal requests (between services) don't need authorized
94:    if (isWebhookEndpoint(ctx) || ctx.i…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qhv3-wjg8-6fx6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1629</id>
    <title>WID-SEC-W-2026-1629 — Budibase: Mehrere Schwachstellen</title>
    <updated>2026-10-03T21:07:44.440420+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Budibase ausnutzen, um Administratorrechte zu erlangen, Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren oder vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1629"/>
  </entry>
</feed>
