8.7
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H
Description
Budibase is an open-source low-code platform. Prior to version 3.33.4, the plugin file upload endpoint (POST /api/plugin/upload) passes the user-supplied filename directly to createTempFolder() without sanitizing path traversal sequences. An attacker with Global Builder privileges can craft a multipart upload with a filename containing ../ to delete arbitrary directories via rmSync and write arbitrary files via tarball extraction to any filesystem path the Node.js process can access. This issue has been patched in version 3.33.4.
Basic Information
ID
CVE-2026-35214
Source
GitHub_M
Published
Apr 3, 2026 at 15:43
Modified
Apr 3, 2026 at 16:04
Affected Product
Vendor
Budibase
Product
budibase
Version
< 3.33.4
Affected Versions
Budibase budibase < 3.33.4