Junglewise Threat Intelligence

CVE-2026-100680: Budibase arbitrary local file read in OpenAPI import

CVE-2026-100680 · Severity: high · CVSS 8.1 · Published 2026-09-26

Technologies: Budibase. Vendors: Budibase.

Executive brief

Budibase, a low-code application platform, failed to properly disable external file resolution when validating OpenAPI/Swagger specifications, allowing authenticated users with builder privileges to read arbitrary files from the server. An attacker with builder access can craft a malicious API specification containing file:// references to extract sensitive data such as environment variables, JWT secrets, API keys, and database credentials, potentially compromising the entire deployment.

Technical details

The vulnerability exists in the OpenAPI import validator (POST /api/queries/import/info) where SwaggerParser.validate() is called without the resolve.external:false option, causing @apidevtools/swagger-parser to default to external=true and enable filesystem resolution. An authenticated builder can embed {"$ref":"file:///etc/passwd"} or similar file:// pointers in the OpenAPI spec to trigger arbitrary local file reads; file contents are returned in the import response or inlined during schema validation. The fix is a one-line change to pass the same resolve options to the validate function as the parse and dereference fallback functions already do.

Affected products

  • Budibase Budibase before 3.45.0

Timeline

  • 2026-09-26: disclosed
  • 2026-09-10: patched: Version 3.45.0 includes the fix

References

Related threats