Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Server: Budibase: SQL Injection via `multipleStatements: true`

0
Critical
Published: 07/24/2026 (07/24/2026, 21:15:02 UTC)
Source: GCVE Database
Product: @budibase/server

Description

A critical SQL injection vulnerability exists in Budibase's MySQL integration due to the configuration setting `multipleStatements: true`. This setting allows execution of multiple SQL statements in a single query, enabling remote attackers to inject and execute arbitrary SQL commands. The vulnerability can lead to severe impacts including data destruction, data theft, privilege escalation, denial of service, and complete database compromise. The issue affects Budibase server versions up to and including 3.38.1. A patch is available that disables multiple statements by setting `multipleStatements: false` in the MySQL integration configuration.

CVSS v3.1

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected software

npmghsa
@budibase/server
Affected versions
<=3.38.1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/25/2026, 23:57:30 UTC

Technical Analysis

Budibase's MySQL integration component is configured with `multipleStatements: true`, which permits execution of multiple SQL statements in a single query. This configuration enables attackers to perform SQL injection attacks by injecting malicious SQL commands through user input fields. The vulnerability is located in the file `packages/server/src/integrations/mysql.ts` at line 173. Exploitation can result in executing destructive commands such as DROP TABLE, unauthorized data exfiltration, privilege escalation, and denial of service. The recommended fix is to set `multipleStatements` to false, preventing execution of multiple statements in a single query.

Potential Impact

The vulnerability allows remote attackers to execute arbitrary SQL commands, leading to potential data destruction (e.g., dropping tables), data theft (e.g., exfiltrating data), privilege escalation within the database, denial of service by disrupting database operations, and complete compromise of the database. These impacts can severely affect the confidentiality, integrity, and availability of the affected systems.

Mitigation Recommendations

A patch is available that disables the `multipleStatements` option by setting it to false in the MySQL integration configuration (`multipleStatements: false`). This change prevents execution of multiple SQL statements in a single query, mitigating the SQL injection risk. Additional workarounds include temporarily disabling the MySQL integration, implementing a web application firewall (WAF) to filter malicious inputs, and restricting database user privileges to limit potential damage.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-q6x4-v3qx-85qw
Osv Schema Version
1.4.0
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
CRITICAL
Cvss Version
3.1

Threat ID: 6a6542309c2644c7f808a752

Added to database: 07/25/2026, 23:09:36 UTC

Last enriched: 07/25/2026, 23:57:30 UTC

Last updated: 07/26/2026, 01:30:05 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses