Server: Budibase has arbitrary file read by workspace-builder via PWA-zip symlink upload (CVE-2026-54352)
Budibase server versions up to 3.39.8 have a critical vulnerability (CVE-2026-54352) allowing workspace builders to read arbitrary files on the server by uploading a crafted PWA zip containing symlinks. The vulnerability arises because the extract-zip library preserves absolute symlink targets, and the icon path validation does not reject symlinks pointing outside the allowed directory. This enables reading sensitive files such as /data/.env containing secrets. The default Docker image runs the server as root, increasing impact. The vulnerability is not present in managed cloud-hosted Budibase tenants where filesystem access is sandboxed. A patch is available.
AI Analysis
Technical Summary
The Budibase server's POST /api/pwa/process-zip endpoint accepts a zip file uploaded by workspace builders, extracts it using [email protected] which preserves absolute symlink targets, and validates icon paths by resolving them against a base directory. However, the validation only checks that the resolved path starts with the base directory and that the target exists, without rejecting symlinks pointing outside the base directory. Consequently, a symlink inside the extracted directory can point to any file readable by the server process. The server then streams the contents of the target file into MinIO storage and serves it via a GET endpoint, effectively allowing arbitrary file read. The default Docker container runs the Node server as root, allowing access to sensitive files such as /data/.env containing secrets like JWT_SECRET and database credentials. This vulnerability affects Budibase server versions up to 3.39.8 and is exploitable by any user with the workspace-builder permission. Managed cloud-hosted Budibase tenants are not affected due to sandboxing. A patch is available to fix this issue.
Potential Impact
An attacker with workspace-builder permissions can read any file on the server that the Node process can open, including sensitive configuration and secret files such as /data/.env, /etc/passwd, and /etc/shadow. This leads to disclosure of critical secrets like JWT_SECRET, internal API keys, database credentials, and other environment variables. The vulnerability can be exploited remotely via the API by uploading a crafted zip file. The default Docker image running the server as root exacerbates the impact by granting access to all root-readable files. This can lead to full compromise of the Budibase deployment.
Mitigation Recommendations
A patch is available for Budibase server to address this vulnerability. Users should upgrade to a fixed version above 3.39.8. Until patched, restrict workspace-builder permissions to trusted users only. Managed cloud-hosted Budibase tenants are not affected as the vendor sandboxes filesystem access. Review vendor advisories for official patch details and apply updates promptly.
Server: Budibase has arbitrary file read by workspace-builder via PWA-zip symlink upload (CVE-2026-54352)
Description
Budibase server versions up to 3.39.8 have a critical vulnerability (CVE-2026-54352) allowing workspace builders to read arbitrary files on the server by uploading a crafted PWA zip containing symlinks. The vulnerability arises because the extract-zip library preserves absolute symlink targets, and the icon path validation does not reject symlinks pointing outside the allowed directory. This enables reading sensitive files such as /data/.env containing secrets. The default Docker image runs the server as root, increasing impact. The vulnerability is not present in managed cloud-hosted Budibase tenants where filesystem access is sandboxed. A patch is available.
CVSS v3.1
Score 9.6critical
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Budibase server's POST /api/pwa/process-zip endpoint accepts a zip file uploaded by workspace builders, extracts it using [email protected] which preserves absolute symlink targets, and validates icon paths by resolving them against a base directory. However, the validation only checks that the resolved path starts with the base directory and that the target exists, without rejecting symlinks pointing outside the base directory. Consequently, a symlink inside the extracted directory can point to any file readable by the server process. The server then streams the contents of the target file into MinIO storage and serves it via a GET endpoint, effectively allowing arbitrary file read. The default Docker container runs the Node server as root, allowing access to sensitive files such as /data/.env containing secrets like JWT_SECRET and database credentials. This vulnerability affects Budibase server versions up to 3.39.8 and is exploitable by any user with the workspace-builder permission. Managed cloud-hosted Budibase tenants are not affected due to sandboxing. A patch is available to fix this issue.
Potential Impact
An attacker with workspace-builder permissions can read any file on the server that the Node process can open, including sensitive configuration and secret files such as /data/.env, /etc/passwd, and /etc/shadow. This leads to disclosure of critical secrets like JWT_SECRET, internal API keys, database credentials, and other environment variables. The vulnerability can be exploited remotely via the API by uploading a crafted zip file. The default Docker image running the server as root exacerbates the impact by granting access to all root-readable files. This can lead to full compromise of the Budibase deployment.
Mitigation Recommendations
A patch is available for Budibase server to address this vulnerability. Users should upgrade to a fixed version above 3.39.8. Until patched, restrict workspace-builder permissions to trusted users only. Managed cloud-hosted Budibase tenants are not affected as the vendor sandboxes filesystem access. Review vendor advisories for official patch details and apply updates promptly.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-w7mq-r738-x278
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-54352"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- CRITICAL
- Cvss Version
- 3.1
Threat ID: 6a7cd3e1bf8831d53917fe4e
Added to database: 08/12/2026, 20:13:21 UTC
Last enriched: 08/12/2026, 21:11:10 UTC
Last updated: 08/13/2026, 01:33:45 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.