Junglewise Threat Intelligence

Budibase SQL injection in MySQL Database Connector via DESCRIBE query

Severity: high · CVSS 7.6 · Published 2026-07-24

Technologies: Budibase @Budibase/Server, @budibase/server (npm). Vendors: Budibase, npm.

Executive brief

Budibase is a platform used to build business applications and connect to various databases. A security flaw in its MySQL connector allows an attacker to execute unauthorized database commands by creating a specially named table in a connected database. When a Budibase administrator performs routine tasks like refreshing the table list, the malicious commands are automatically triggered, potentially leading to data loss or unauthorized access.

Technical details

A SQL injection vulnerability exists in the Budibase MySQL integration due to improper neutralization of backticks during table introspection. The application enables 'multipleStatements: true' on the MySQL connection and interpolates table names directly into a 'DESCRIBE' query. An attacker with the ability to create tables in the underlying MySQL database can use a malicious table name containing unescaped backticks and semicolons to break out of the original query and execute arbitrary SQL. This is triggered when a Budibase administrator performs schema discovery or refreshes the datasource. The issue is fixed in version 3.39.18.

Affected products

  • Budibase @budibase/server <= 3.38.1

Timeline

  • 2026-07-22: disclosed
  • 2026-07-24: advisory: Published to GitHub Advisory Database
  • 2026-07-24: patched: Version 3.39.18 released

References

Related threats