<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 08:13:47 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-352819</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352819</link>
      <description>EUVD-2026-352819</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352819</guid>
    </item>
    <item>
      <title>fkie_cve-2026-73408</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73408</link>
      <description>&lt;p&gt;Budibase is an open-source low-code platform. Prior to 3.39.18, packages/server/src/integrations/mysql.ts enabled multipleStatements and inserted an unescaped tableName into a DESCRIBE statement. An attacker able to create a MySQL table with a backtick and stacked statement in its name could wait for a Budibase administrator to run schema discovery, causing the second statement to execute. The fix applies quoteMySqlIdentifier before constructing the query. This issue is fixed in version 3.39.18.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Budibase is an open-source low-code platform. Prior to 3.39.18, packages/server/src/integrations/mysql.ts enabled multipleStatements and inserted an unescaped tableName into a DESCRIBE statement. An attacker able to create a MySQL table with a backtick and stacked statement in its name could wait for a Budibase administrator to run schema discovery, causing the second statement to execute. The fix applies quoteMySqlIdentifier before constructing the query. This issue is fixed in version 3.39.18.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-73408</guid>
    </item>
    <item>
      <title>GHSA-2xgg-r2wc-c5r2 — Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2xgg-r2wc-c5r2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @budibase/server&lt;/p&gt;
&lt;p&gt;### Summary
**This is a related but independently fixable vulnerability to GHSA-qqf5-x7mj-v43p
(PostgreSQL SQL injection), reported in the same original disclosure and
split per GitHub CNA guidance (rule 4.2.11) since it affects a separate
integration, has a distinct attack precondition, and requires a separate
patch.**&lt;/p&gt;
&lt;p&gt;The MySQL integration enables `multipleStatements: true` on the connection,
permitting semicolon-separated multi-statement execution. During table
introspection, table names retrieved from `INFORMATION_SCHEMA.TABLES` are
interpolated into a `DESCRIBE` query wrapped in backticks, but embedded
backticks in the table name are never escaped — allowing a malicious table
name to break out and inject a second, attacker-controlled statement.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Vulnerable Code:**
File: `packages/server/src/integrations/mysql.ts`, lines 172, 305&lt;/p&gt;
&lt;p&gt;```typescript
this.config = { ...config, multipleStatements: true, ... }  // line 172
...
{ sql: `DESCRIBE \`${tableName}\`;` }  // line 305 — backtick NOT escaped
```&lt;/p&gt;
&lt;p&gt;Because `multipleStatements` is enabled, any statement appended after the
backtick break-out executes as a second query in the same round trip.&lt;/p&gt;
&lt;p&gt;### Step-by-Step Reproduction
1. An attacker with the ability to create tables in the target MySQL
   database (e.g. a lower-privileged database user, or a malicious actor in
   a multi-tenant database) creates a table named:
   ``foo`; DROP TABLE users; --``
2. In Budibase, an administrator triggers schema introspection…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @budibase/server&lt;/p&gt;
&lt;p&gt;### Summary
**This is a related but independently fixable vulnerability to GHSA-qqf5-x7mj-v43p
(PostgreSQL SQL injection), reported in the same original disclosure and
split per GitHub CNA guidance (rule 4.2.11) since it affects a separate
integration, has a distinct attack precondition, and requires a separate
patch.**&lt;/p&gt;
&lt;p&gt;The MySQL integration enables `multipleStatements: true` on the connection,
permitting semicolon-separated multi-statement execution. During table
introspection, table names retrieved from `INFORMATION_SCHEMA.TABLES` are
interpolated into a `DESCRIBE` query wrapped in backticks, but embedded
backticks in the table name are never escaped — allowing a malicious table
name to break out and inject a second, attacker-controlled statement.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Vulnerable Code:**
File: `packages/server/src/integrations/mysql.ts`, lines 172, 305&lt;/p&gt;
&lt;p&gt;```typescript
this.config = { ...config, multipleStatements: true, ... }  // line 172
...
{ sql: `DESCRIBE \`${tableName}\`;` }  // line 305 — backtick NOT escaped
```&lt;/p&gt;
&lt;p&gt;Because `multipleStatements` is enabled, any statement appended after the
backtick break-out executes as a second query in the same round trip.&lt;/p&gt;
&lt;p&gt;### Step-by-Step Reproduction
1. An attacker with the ability to create tables in the target MySQL
   database (e.g. a lower-privileged database user, or a malicious actor in
   a multi-tenant database) creates a table named:
   ``foo`; DROP TABLE users; --``
2. In Budibase, an administrator triggers schema introspection…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2xgg-r2wc-c5r2</guid>
    </item>
  </channel>
</rss>
