Budibase Server Vulnerability: Arbitrary File Read via PWA Zip Upload
- Severity
- HIGH
- Affected component
- @budibase/server (npm)
- Affected versions
- < 3.33.4 or <= 3.38.1 or < 3.39.0 or < 3.38.1 or < 3.39.0 or < 3.38.1 or < 2.20.0 or < 3.39.0 or <= 3.38.1 or < 3.39.0 or < 3.23.32 or < 3.39.12 or <= 3.38.1 or <= 3.38.1 or < 3.35.3 or < 3.33.4 or < 3.39.25 or < 3.38.1 or < 3.39.0 or <= 3.38.1 or < 3.33.4 or <= 3.38.1 or <= 3.38.1 or <= 3.38.1 or <= 3.38.1 or < 3.39.2 or <= 3.38.1 or <= 3.38.1 or <= 3.38.1 or <= 3.38.1 or <= 3.38.1 or < 3.39.0 or <= 3.38.1 or < 3.39.9 or < 3.34.8 or <= 3.38.1 or < 3.39.0 or < 3.39.9 or <= 3.38.1 or <= 3.38.1
- Patched version
- Not yet available
An early warning has been issued for a high-severity vulnerability in the Budibase server. This vulnerability, tracked as GHSA-W7MQ-R738-X278, allows arbitrary file read via a crafted PWA zip upload.
What happened
The Budibase server reportedly allows arbitrary file read via a crafted PWA zip upload. This vulnerability enables access to sensitive files such as /data/.env. The issue is under investigation and has not yet been exploited in the wild. The affected component is @budibase/server (npm) with various version ranges identified as vulnerable.
Users of Budibase server are advised to review the affected version ranges and upgrade to a version that fixes this vulnerability. Additionally, access controls for the workspace-builder permission should be reviewed to mitigate potential risks.
What to do about it
- Upgrade to a version of Budibase server that fixes this vulnerability.
- Review and strengthen access controls for the workspace-builder permission.
- Monitor the primary sources for updates on this vulnerability.
- Consult the primary sources for the most current information on affected and patched versions.
How 0Day would have caught this
@budibase/server is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if you are using @budibase/server (npm) with versions less than 3.33.4, 3.38.1, 3.39.0, 3.23.32, 3.39.12, 3.35.3, 3.39.25, 3.39.2, 3.39.9, 3.34.8, or 3.39.0.
What should I do right now?
Upgrade to a version of Budibase server that fixes this vulnerability and review access controls for the workspace-builder permission.
Is there an official fix available?
No official fix has been published yet. Monitor the primary sources for updates.