Server: Budibase: SQL Injection via `multipleStatements: true`
A critical SQL injection vulnerability exists in Budibase's MySQL integration due to the configuration setting `multipleStatements: true`. This setting allows execution of multiple SQL statements in a single query, enabling remote attackers to inject and execute arbitrary SQL commands. The vulnerability can lead to severe impacts including data destruction, data theft, privilege escalation, denial of service, and complete database compromise. The issue affects Budibase server versions up to and including 3.38.1. A patch is available that disables multiple statements by setting `multipleStatements: false` in the MySQL integration configuration.
AI Analysis
Technical Summary
Budibase's MySQL integration component is configured with `multipleStatements: true`, which permits execution of multiple SQL statements in a single query. This configuration enables attackers to perform SQL injection attacks by injecting malicious SQL commands through user input fields. The vulnerability is located in the file `packages/server/src/integrations/mysql.ts` at line 173. Exploitation can result in executing destructive commands such as DROP TABLE, unauthorized data exfiltration, privilege escalation, and denial of service. The recommended fix is to set `multipleStatements` to false, preventing execution of multiple statements in a single query.
Potential Impact
The vulnerability allows remote attackers to execute arbitrary SQL commands, leading to potential data destruction (e.g., dropping tables), data theft (e.g., exfiltrating data), privilege escalation within the database, denial of service by disrupting database operations, and complete compromise of the database. These impacts can severely affect the confidentiality, integrity, and availability of the affected systems.
Mitigation Recommendations
A patch is available that disables the `multipleStatements` option by setting it to false in the MySQL integration configuration (`multipleStatements: false`). This change prevents execution of multiple SQL statements in a single query, mitigating the SQL injection risk. Additional workarounds include temporarily disabling the MySQL integration, implementing a web application firewall (WAF) to filter malicious inputs, and restricting database user privileges to limit potential damage.
Server: Budibase: SQL Injection via `multipleStatements: true`
Description
A critical SQL injection vulnerability exists in Budibase's MySQL integration due to the configuration setting `multipleStatements: true`. This setting allows execution of multiple SQL statements in a single query, enabling remote attackers to inject and execute arbitrary SQL commands. The vulnerability can lead to severe impacts including data destruction, data theft, privilege escalation, denial of service, and complete database compromise. The issue affects Budibase server versions up to and including 3.38.1. A patch is available that disables multiple statements by setting `multipleStatements: false` in the MySQL integration configuration.
CVSS v3.1
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Budibase's MySQL integration component is configured with `multipleStatements: true`, which permits execution of multiple SQL statements in a single query. This configuration enables attackers to perform SQL injection attacks by injecting malicious SQL commands through user input fields. The vulnerability is located in the file `packages/server/src/integrations/mysql.ts` at line 173. Exploitation can result in executing destructive commands such as DROP TABLE, unauthorized data exfiltration, privilege escalation, and denial of service. The recommended fix is to set `multipleStatements` to false, preventing execution of multiple statements in a single query.
Potential Impact
The vulnerability allows remote attackers to execute arbitrary SQL commands, leading to potential data destruction (e.g., dropping tables), data theft (e.g., exfiltrating data), privilege escalation within the database, denial of service by disrupting database operations, and complete compromise of the database. These impacts can severely affect the confidentiality, integrity, and availability of the affected systems.
Mitigation Recommendations
A patch is available that disables the `multipleStatements` option by setting it to false in the MySQL integration configuration (`multipleStatements: false`). This change prevents execution of multiple SQL statements in a single query, mitigating the SQL injection risk. Additional workarounds include temporarily disabling the MySQL integration, implementing a web application firewall (WAF) to filter malicious inputs, and restricting database user privileges to limit potential damage.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-q6x4-v3qx-85qw
- Osv Schema Version
- 1.4.0
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- CRITICAL
- Cvss Version
- 3.1
Threat ID: 6a6542309c2644c7f808a752
Added to database: 07/25/2026, 23:09:36 UTC
Last enriched: 07/25/2026, 23:57:30 UTC
Last updated: 07/26/2026, 01:30:05 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.