<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 21:07:40 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-322422</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-322422</link>
      <description>EUVD-2026-322422</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-322422</guid>
    </item>
    <item>
      <title>fkie_cve-2026-48151</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48151</link>
      <description>&lt;p&gt;Budibase is an open-source low-code platform. Prior to 3.39.0, the webhook schema-building endpoint is registered under builderRoutes, but the generic authorization middleware skips authorization for all paths matching /api/webhooks/schema. As a result, an unauthenticated caller can update the body schema for a known webhook and mutate the corresponding automation trigger output schema. This vulnerability is fixed in 3.39.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Budibase is an open-source low-code platform. Prior to 3.39.0, the webhook schema-building endpoint is registered under builderRoutes, but the generic authorization middleware skips authorization for all paths matching /api/webhooks/schema. As a result, an unauthenticated caller can update the body schema for a known webhook and mutate the corresponding automation trigger output schema. This vulnerability is fixed in 3.39.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-48151</guid>
    </item>
    <item>
      <title>GHSA-qhv3-wjg8-6fx6 — Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schema</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qhv3-wjg8-6fx6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @budibase/server&lt;/p&gt;
&lt;p&gt;The webhook schema-building endpoint is registered under `builderRoutes`, but the generic authorization middleware skips authorization for all paths matching `/api/webhooks/schema`. As a result, an unauthenticated caller can update the body schema for a known webhook and mutate the corresponding automation trigger output schema.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The route appears to be builder-only:&lt;/p&gt;
&lt;p&gt;- `packages/server/src/api/routes/webhook.ts:5-9`&lt;/p&gt;
&lt;p&gt;```ts
5:builderRoutes
6:  .get(&amp;#34;/api/webhooks&amp;#34;, controller.fetch)
7:  .put(&amp;#34;/api/webhooks&amp;#34;, webhookValidator(), controller.save)
8:  .delete(&amp;#34;/api/webhooks/:id/:rev&amp;#34;, controller.destroy)
9:  .post(&amp;#34;/api/webhooks/schema/:instance/:id&amp;#34;, controller.buildSchema)
```&lt;/p&gt;
&lt;p&gt;However, webhook endpoint detection explicitly includes `schema`:&lt;/p&gt;
&lt;p&gt;- `packages/server/src/middleware/utils.ts:3-9`&lt;/p&gt;
&lt;p&gt;```ts
3:const WEBHOOK_ENDPOINTS = new RegExp(
4:  &amp;#34;^/api/webhooks/(trigger|schema|discord|ms-teams|slack)(/|$)&amp;#34;
5:)
6:
7:export function isWebhookEndpoint(ctx: UserCtx): boolean {
8:  const path = ctx.path || ctx.request.url.split(&amp;#34;?&amp;#34;)[0]
9:  return WEBHOOK_ENDPOINTS.test(path)
```&lt;/p&gt;
&lt;p&gt;The authorization middleware bypasses all webhook endpoints before checking `ctx.user` or permissions:&lt;/p&gt;
&lt;p&gt;- `packages/server/src/middleware/authorized.ts:90-99`&lt;/p&gt;
&lt;p&gt;```ts
90:  ) =&amp;gt;
91:  async (ctx: UserCtx, next: any) =&amp;gt; {
92:    // webhooks don&amp;#39;t need authentication, each webhook unique
93:    // also internal requests (between services) don&amp;#39;t need authorized
94:    if (isWebhookEndpoint(ctx) || ctx.i…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @budibase/server&lt;/p&gt;
&lt;p&gt;The webhook schema-building endpoint is registered under `builderRoutes`, but the generic authorization middleware skips authorization for all paths matching `/api/webhooks/schema`. As a result, an unauthenticated caller can update the body schema for a known webhook and mutate the corresponding automation trigger output schema.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The route appears to be builder-only:&lt;/p&gt;
&lt;p&gt;- `packages/server/src/api/routes/webhook.ts:5-9`&lt;/p&gt;
&lt;p&gt;```ts
5:builderRoutes
6:  .get(&amp;#34;/api/webhooks&amp;#34;, controller.fetch)
7:  .put(&amp;#34;/api/webhooks&amp;#34;, webhookValidator(), controller.save)
8:  .delete(&amp;#34;/api/webhooks/:id/:rev&amp;#34;, controller.destroy)
9:  .post(&amp;#34;/api/webhooks/schema/:instance/:id&amp;#34;, controller.buildSchema)
```&lt;/p&gt;
&lt;p&gt;However, webhook endpoint detection explicitly includes `schema`:&lt;/p&gt;
&lt;p&gt;- `packages/server/src/middleware/utils.ts:3-9`&lt;/p&gt;
&lt;p&gt;```ts
3:const WEBHOOK_ENDPOINTS = new RegExp(
4:  &amp;#34;^/api/webhooks/(trigger|schema|discord|ms-teams|slack)(/|$)&amp;#34;
5:)
6:
7:export function isWebhookEndpoint(ctx: UserCtx): boolean {
8:  const path = ctx.path || ctx.request.url.split(&amp;#34;?&amp;#34;)[0]
9:  return WEBHOOK_ENDPOINTS.test(path)
```&lt;/p&gt;
&lt;p&gt;The authorization middleware bypasses all webhook endpoints before checking `ctx.user` or permissions:&lt;/p&gt;
&lt;p&gt;- `packages/server/src/middleware/authorized.ts:90-99`&lt;/p&gt;
&lt;p&gt;```ts
90:  ) =&amp;gt;
91:  async (ctx: UserCtx, next: any) =&amp;gt; {
92:    // webhooks don&amp;#39;t need authentication, each webhook unique
93:    // also internal requests (between services) don&amp;#39;t need authorized
94:    if (isWebhookEndpoint(ctx) || ctx.i…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qhv3-wjg8-6fx6</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1629 — Budibase: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1629</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Budibase ausnutzen, um Administratorrechte zu erlangen, Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Budibase ausnutzen, um Administratorrechte zu erlangen, Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1629</guid>
    </item>
  </channel>
</rss>
