Junglewise Threat Intelligence

CVE-2026-100682: Budibase Server arbitrary file write via ZIP symlink traversal

CVE-2026-100682 · Severity: high · CVSS 8.8 · Published 2026-09-26

Technologies: Budibase Server. Vendors: Budibase.

Executive brief

Budibase Server is a low-code platform that allows users with BUILDER role to upload Progressive Web App (PWA) icons. An attacker with BUILDER role can craft a malicious ZIP archive that exploits improper symlink handling to write arbitrary files as root, leading to remote code execution. Since Budibase containers run as root by default, this vulnerability enables complete system compromise.

Technical details

The PWA icon upload endpoint in Budibase uses extract-zip@2.0.1, which validates only the directory component of ZIP entries but not the leaf filename, failing to detect symlinks. An attacker can place a symlink at the leaf entry pointing to an arbitrary absolute path, followed by a duplicate regular file entry of the same name, causing the extractor to write through the symlink. The vulnerability requires BUILDER role authorization and affects versions before 3.45.0.

Affected products

  • Budibase Server before 3.45.0

Timeline

  • 2026-09-26: disclosed: Public disclosure via NVD and GitHub Security Advisory
  • 2026-09-10: patched: Patch released in version 3.45.0

References

Related threats