Executive brief
A security flaw in Budibase, a platform for building internal business applications, allows standard users to bypass intended restrictions and upload files to Amazon S3 storage. This could allow an unauthorized user to overwrite or place malicious files in any storage bucket accessible by the system's credentials. This poses a risk to data integrity and could lead to the distribution of malicious content within an organization.
Technical details
An authorization regression in Budibase v3.39.4 changed the S3 attachment upload endpoint from 'BUILDER' level to 'TABLE/WRITE' level. This allows any user with 'BASIC' app permissions to request S3 PutObject presigned URLs via the '/api/attachments/:datasourceId/url' route. Furthermore, the controller fails to validate the 'bucket' parameter against the datasource's configuration, allowing an attacker to generate upload URLs for any S3 bucket accessible by the stored IAM credentials. This is classified as Incorrect Authorization (CWE-863). A fix is available in version 3.40.0.
Affected products
- Budibase @budibase/server <= 3.38.1
Timeline
- 2026-07-22: disclosed
- 2026-07-24: advisory: GitHub Advisory GHSA-xcx6-4f2g-hhgx published