<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T07:50:23.748878+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-354881</id>
    <title>EUVD-2026-354881</title>
    <updated>2026-10-03T07:50:23.796300+00:00</updated>
    <content>EUVD-2026-354881</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-354881"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54356</id>
    <title>fkie_cve-2026-54356</title>
    <updated>2026-10-03T07:50:23.796335+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Budibase is an open-source low-code platform. Prior to 3.41.3, POST /api/attachments/:datasourceId/url in packages/server/src/api/routes/static.ts and packages/server/src/api/controllers/static/index.ts allows an authenticated published-app user with the BASIC role to supply attacker-controlled bucket and key values and obtain signedUrl and publicUrl values backed by stored S3 datasource credentials. This issue is fixed in version 3.41.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-54356"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6x9p-4r67-5gjx</id>
    <title>GHSA-6x9p-4r67-5gjx — Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url`</title>
    <updated>2026-10-03T07:50:23.796370+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @budibase/server</p>
<p>### Summary
Budibase 3.39.7 allows a low-privilege authenticated published-app user with the built-in BASIC role to obtain arbitrary S3 pre-signed upload URLs backed by a workspace datasource's stored server-side credentials.</p>
<p>The affected endpoint is:</p>
<p>`POST /api/attachments/:datasourceId/url`</p>
<p>The caller can control:
```text
bucket
key
```
and receives:
```text
signedUrl
publicUrl
```</p>
<p>This lets a low-privilege published-app user mint S3 `PUT` URLs using server-side datasource credentials for attacker-chosen object destinations.</p>
<p>Steps:</p>
<p>1. Log in as an admin user.
2. Create a new app/workspace.
3. In the development app context, create an S3 datasource with valid credentials.
4. Publish the app.
5. Create a low-privilege user with the built-in BASIC role on the published production app ID.
6. Log in as that BASIC user.
7. Send:
`POST /api/attachments/&lt;datasourceId&gt;/url`</p>
<p>with:
```json
{"bucket":"foo","key":"bar"}
```
and the published app header:
```text
x-budibase-app-id: &lt;published_app_id&gt;
```
Observe a successful response containing:
```text
signedUrl
publicUrl
```</p>
<p>### Observed result</p>
<p>The following behavior:</p>
<p>dev BASIC request: 403 User does not have permission
app publish: SUCCESS
prod BASIC request: 200 OK
Example confirmed runtime values from the final successful run:
```text
prodAppId: app_e6b4cdc6cd6949969a83ff11eee88c5a
datasourceId: datasource_0cec491b26a742468257c62382aa3284
publicUrl: https://foo.s3.eu-west-1.amazonaws.com/bar
```
The returned signedUrl cont…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6x9p-4r67-5gjx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2849</id>
    <title>WID-SEC-W-2026-2849 — Budibase: Mehrere Schwachstellen</title>
    <updated>2026-10-03T07:50:23.796421+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Budibase ausnutzen, um Dateien zu manipulieren, vertrauliche Daten offenzulegen, erweiterte Berechtigungen zu erlangen und Sicherheitsmaßnahmen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2849"/>
  </entry>
</feed>
