<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 20:21:29 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-330852</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-330852</link>
      <description>EUVD-2026-330852</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-330852</guid>
    </item>
    <item>
      <title>fkie_cve-2026-50136</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-50136</link>
      <description>&lt;p&gt;Budibase is an open-source low-code platform. Prior to 3.39.3, the application server exposes an unauthenticated endpoint that generates S3 PutObject presigned URLs using credentials stored in a workspace datasource. The route is protected only by the recaptcha middleware and does not require authentication, table permission, datasource permission, or builder access. A public caller who knows a workspace ID and S3 datasource ID can request a signed upload URL for attacker-controlled bucket and key values. This vulnerability is fixed in 3.39.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Budibase is an open-source low-code platform. Prior to 3.39.3, the application server exposes an unauthenticated endpoint that generates S3 PutObject presigned URLs using credentials stored in a workspace datasource. The route is protected only by the recaptcha middleware and does not require authentication, table permission, datasource permission, or builder access. A public caller who knows a workspace ID and S3 datasource ID can request a signed upload URL for attacker-controlled bucket and key values. This vulnerability is fixed in 3.39.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-50136</guid>
    </item>
    <item>
      <title>GHSA-jj36-r9w3-3pfh — Budibase: Unauthenticated S3 signed upload URL generation allows arbitrary writes with stored datasource credentials</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jj36-r9w3-3pfh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @budibase/server&lt;/p&gt;
&lt;p&gt;The application server exposes an unauthenticated endpoint that generates S3 `PutObject` presigned URLs using credentials stored in a workspace datasource. The route is protected only by the recaptcha middleware and does not require authentication, table permission, datasource permission, or builder access. A public caller who knows a workspace ID and S3 datasource ID can request a signed upload URL for attacker-controlled bucket and key values.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The static route registers the signed upload URL endpoint with only `recaptcha` before the controller:&lt;/p&gt;
&lt;p&gt;- `packages/server/src/api/routes/static.ts:44-48`&lt;/p&gt;
&lt;p&gt;```ts
44:  .post(
45:    &amp;#34;/api/attachments/:datasourceId/url&amp;#34;,
46:    recaptcha,
47:    controller.getSignedUploadURL
48:  )
```&lt;/p&gt;
&lt;p&gt;The controller loads the datasource by `datasourceId` with enriched secret values:&lt;/p&gt;
&lt;p&gt;- `packages/server/src/api/controllers/static/index.ts:590-598`&lt;/p&gt;
&lt;p&gt;```ts
590:export const getSignedUploadURL = async function (
591:  ctx: Ctx&amp;lt;GetSignedUploadUrlRequest, GetSignedUploadUrlResponse&amp;gt;
592:) {
593:  // Ensure datasource is valid
594:  let datasource
595:  try {
596:    const { datasourceId } = ctx.params
597:    datasource = await sdk.datasources.get(datasourceId, { enriched: true })
598:    if (!datasource) {
```&lt;/p&gt;
&lt;p&gt;The request body controls `bucket` and `key`, and the server signs a PUT URL using the stored datasource credentials:&lt;/p&gt;
&lt;p&gt;- `packages/server/src/api/controllers/static/index.ts:609-629`&lt;/p&gt;
&lt;p&gt;```ts
609:  if (datasource?.source === &amp;#34;S3&amp;#34;) {
610:…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @budibase/server&lt;/p&gt;
&lt;p&gt;The application server exposes an unauthenticated endpoint that generates S3 `PutObject` presigned URLs using credentials stored in a workspace datasource. The route is protected only by the recaptcha middleware and does not require authentication, table permission, datasource permission, or builder access. A public caller who knows a workspace ID and S3 datasource ID can request a signed upload URL for attacker-controlled bucket and key values.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The static route registers the signed upload URL endpoint with only `recaptcha` before the controller:&lt;/p&gt;
&lt;p&gt;- `packages/server/src/api/routes/static.ts:44-48`&lt;/p&gt;
&lt;p&gt;```ts
44:  .post(
45:    &amp;#34;/api/attachments/:datasourceId/url&amp;#34;,
46:    recaptcha,
47:    controller.getSignedUploadURL
48:  )
```&lt;/p&gt;
&lt;p&gt;The controller loads the datasource by `datasourceId` with enriched secret values:&lt;/p&gt;
&lt;p&gt;- `packages/server/src/api/controllers/static/index.ts:590-598`&lt;/p&gt;
&lt;p&gt;```ts
590:export const getSignedUploadURL = async function (
591:  ctx: Ctx&amp;lt;GetSignedUploadUrlRequest, GetSignedUploadUrlResponse&amp;gt;
592:) {
593:  // Ensure datasource is valid
594:  let datasource
595:  try {
596:    const { datasourceId } = ctx.params
597:    datasource = await sdk.datasources.get(datasourceId, { enriched: true })
598:    if (!datasource) {
```&lt;/p&gt;
&lt;p&gt;The request body controls `bucket` and `key`, and the server signs a PUT URL using the stored datasource credentials:&lt;/p&gt;
&lt;p&gt;- `packages/server/src/api/controllers/static/index.ts:609-629`&lt;/p&gt;
&lt;p&gt;```ts
609:  if (datasource?.source === &amp;#34;S3&amp;#34;) {
610:…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jj36-r9w3-3pfh</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1714 — Budibase: Mehrere Schwachstellen ermöglichen Manipulation von Dateien</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1714</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Budibase ausnutzen, um Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Budibase ausnutzen, um Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1714</guid>
    </item>
  </channel>
</rss>
