<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:11:51 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-354881</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-354881</link>
      <description>EUVD-2026-354881</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-354881</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54356</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54356</link>
      <description>&lt;p&gt;Budibase is an open-source low-code platform. Prior to 3.41.3, POST /api/attachments/:datasourceId/url in packages/server/src/api/routes/static.ts and packages/server/src/api/controllers/static/index.ts allows an authenticated published-app user with the BASIC role to supply attacker-controlled bucket and key values and obtain signedUrl and publicUrl values backed by stored S3 datasource credentials. This issue is fixed in version 3.41.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Budibase is an open-source low-code platform. Prior to 3.41.3, POST /api/attachments/:datasourceId/url in packages/server/src/api/routes/static.ts and packages/server/src/api/controllers/static/index.ts allows an authenticated published-app user with the BASIC role to supply attacker-controlled bucket and key values and obtain signedUrl and publicUrl values backed by stored S3 datasource credentials. This issue is fixed in version 3.41.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54356</guid>
    </item>
    <item>
      <title>GHSA-6x9p-4r67-5gjx — Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url`</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6x9p-4r67-5gjx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @budibase/server&lt;/p&gt;
&lt;p&gt;### Summary
Budibase 3.39.7 allows a low-privilege authenticated published-app user with the built-in BASIC role to obtain arbitrary S3 pre-signed upload URLs backed by a workspace datasource&amp;#39;s stored server-side credentials.&lt;/p&gt;
&lt;p&gt;The affected endpoint is:&lt;/p&gt;
&lt;p&gt;`POST /api/attachments/:datasourceId/url`&lt;/p&gt;
&lt;p&gt;The caller can control:
```text
bucket
key
```
and receives:
```text
signedUrl
publicUrl
```&lt;/p&gt;
&lt;p&gt;This lets a low-privilege published-app user mint S3 `PUT` URLs using server-side datasource credentials for attacker-chosen object destinations.&lt;/p&gt;
&lt;p&gt;Steps:&lt;/p&gt;
&lt;p&gt;1. Log in as an admin user.
2. Create a new app/workspace.
3. In the development app context, create an S3 datasource with valid credentials.
4. Publish the app.
5. Create a low-privilege user with the built-in BASIC role on the published production app ID.
6. Log in as that BASIC user.
7. Send:
`POST /api/attachments/&amp;lt;datasourceId&amp;gt;/url`&lt;/p&gt;
&lt;p&gt;with:
```json
{&amp;#34;bucket&amp;#34;:&amp;#34;foo&amp;#34;,&amp;#34;key&amp;#34;:&amp;#34;bar&amp;#34;}
```
and the published app header:
```text
x-budibase-app-id: &amp;lt;published_app_id&amp;gt;
```
Observe a successful response containing:
```text
signedUrl
publicUrl
```&lt;/p&gt;
&lt;p&gt;### Observed result&lt;/p&gt;
&lt;p&gt;The following behavior:&lt;/p&gt;
&lt;p&gt;dev BASIC request: 403 User does not have permission
app publish: SUCCESS
prod BASIC request: 200 OK
Example confirmed runtime values from the final successful run:
```text
prodAppId: app_e6b4cdc6cd6949969a83ff11eee88c5a
datasourceId: datasource_0cec491b26a742468257c62382aa3284
publicUrl: https://foo.s3.eu-west-1.amazonaws.com/bar
```
The returned signedUrl cont…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @budibase/server&lt;/p&gt;
&lt;p&gt;### Summary
Budibase 3.39.7 allows a low-privilege authenticated published-app user with the built-in BASIC role to obtain arbitrary S3 pre-signed upload URLs backed by a workspace datasource&amp;#39;s stored server-side credentials.&lt;/p&gt;
&lt;p&gt;The affected endpoint is:&lt;/p&gt;
&lt;p&gt;`POST /api/attachments/:datasourceId/url`&lt;/p&gt;
&lt;p&gt;The caller can control:
```text
bucket
key
```
and receives:
```text
signedUrl
publicUrl
```&lt;/p&gt;
&lt;p&gt;This lets a low-privilege published-app user mint S3 `PUT` URLs using server-side datasource credentials for attacker-chosen object destinations.&lt;/p&gt;
&lt;p&gt;Steps:&lt;/p&gt;
&lt;p&gt;1. Log in as an admin user.
2. Create a new app/workspace.
3. In the development app context, create an S3 datasource with valid credentials.
4. Publish the app.
5. Create a low-privilege user with the built-in BASIC role on the published production app ID.
6. Log in as that BASIC user.
7. Send:
`POST /api/attachments/&amp;lt;datasourceId&amp;gt;/url`&lt;/p&gt;
&lt;p&gt;with:
```json
{&amp;#34;bucket&amp;#34;:&amp;#34;foo&amp;#34;,&amp;#34;key&amp;#34;:&amp;#34;bar&amp;#34;}
```
and the published app header:
```text
x-budibase-app-id: &amp;lt;published_app_id&amp;gt;
```
Observe a successful response containing:
```text
signedUrl
publicUrl
```&lt;/p&gt;
&lt;p&gt;### Observed result&lt;/p&gt;
&lt;p&gt;The following behavior:&lt;/p&gt;
&lt;p&gt;dev BASIC request: 403 User does not have permission
app publish: SUCCESS
prod BASIC request: 200 OK
Example confirmed runtime values from the final successful run:
```text
prodAppId: app_e6b4cdc6cd6949969a83ff11eee88c5a
datasourceId: datasource_0cec491b26a742468257c62382aa3284
publicUrl: https://foo.s3.eu-west-1.amazonaws.com/bar
```
The returned signedUrl cont…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6x9p-4r67-5gjx</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2849 — Budibase: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2849</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Budibase ausnutzen, um Dateien zu manipulieren, vertrauliche Daten offenzulegen, erweiterte Berechtigungen zu erlangen und Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Budibase ausnutzen, um Dateien zu manipulieren, vertrauliche Daten offenzulegen, erweiterte Berechtigungen zu erlangen und Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2849</guid>
    </item>
  </channel>
</rss>
