Executive brief
Budibase is a platform used to build business applications and connect to various databases. A security flaw in its MySQL connector allows an attacker to execute unauthorized database commands by creating a specially named table in a connected database. When a Budibase administrator performs routine tasks like refreshing the table list, the malicious commands are automatically triggered, potentially leading to data loss or unauthorized access.
Technical details
A SQL injection vulnerability exists in the Budibase MySQL integration due to improper neutralization of backticks during table introspection. The application enables 'multipleStatements: true' on the MySQL connection and interpolates table names directly into a 'DESCRIBE' query. An attacker with the ability to create tables in the underlying MySQL database can use a malicious table name containing unescaped backticks and semicolons to break out of the original query and execute arbitrary SQL. This is triggered when a Budibase administrator performs schema discovery or refreshes the datasource. The issue is fixed in version 3.39.18.
Affected products
- Budibase @budibase/server <= 3.38.1
Timeline
- 2026-07-22: disclosed
- 2026-07-24: advisory: Published to GitHub Advisory Database
- 2026-07-24: patched: Version 3.39.18 released