Executive brief
Budibase Server is a low-code platform that allows users with BUILDER role to upload Progressive Web App (PWA) icons. An attacker with BUILDER role can craft a malicious ZIP archive that exploits improper symlink handling to write arbitrary files as root, leading to remote code execution. Since Budibase containers run as root by default, this vulnerability enables complete system compromise.
Technical details
The PWA icon upload endpoint in Budibase uses extract-zip@2.0.1, which validates only the directory component of ZIP entries but not the leaf filename, failing to detect symlinks. An attacker can place a symlink at the leaf entry pointing to an arbitrary absolute path, followed by a duplicate regular file entry of the same name, causing the extractor to write through the symlink. The vulnerability requires BUILDER role authorization and affects versions before 3.45.0.
Affected products
- Budibase Server before 3.45.0
Timeline
- 2026-09-26: disclosed: Public disclosure via NVD and GitHub Security Advisory
- 2026-09-10: patched: Patch released in version 3.45.0