๐Ÿ” CVE Alert

CVE-2026-25044

UNKNOWN 0.0

Budibase: Command Injection in Bash Automation Step

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Budibase is an open-source low-code platform. Prior to version 3.33.4, the bash automation step executes user-provided commands using execSync without proper sanitization or validation. User input is processed through processStringSync which allows template interpolation, potentially allowing arbitrary command execution. This issue has been patched in version 3.33.4.

CWE CWE-78
Vendor budibase
Product budibase
Published Apr 3, 2026
Last Updated Apr 3, 2026
Stay Ahead of the Next One

Get instant alerts for budibase budibase

Be the first to know when new unknown vulnerabilities affecting budibase budibase are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Budibase / budibase
< 3.33.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Budibase/budibase/security/advisories/GHSA-gjw9-34gf-rp6m github.com: https://github.com/Budibase/budibase/releases/tag/3.33.2