Executive brief
Budibase's legacy V1 Views API fails to validate the "calculation" parameter before using it in a CouchDB database query function, allowing authenticated users with Builder permissions to inject malicious JavaScript code. When a view is queried, this injected code runs in CouchDB's JavaScript engine and can access or exfiltrate database records. The vulnerability requires authenticated access with Builder role permissions and is limited to CouchDB's sandbox environment, preventing direct system compromise but enabling unauthorized data access.
Technical details
The vulnerability is a code injection flaw (CWE-94) in the V1 Views API endpoint POST /api/views. The viewBuilder function in packages/server/src/api/controllers/view/viewBuilder.ts interpolates an unsanitized "calculation" parameter directly into a CouchDB reduce function definition via template string interpolation (reduce: `_${calculation}`), with no allowlist validation despite SCHEMA_MAP defining valid values (sum, count, stats). The affected V1 route lacks request body validation via Joi, unlike the patched V2 endpoint. An authenticated attacker with Builder role can submit a crafted view creation request containing JavaScript payload in the calculation field; when the view is queried, CouchDB's SpiderMonkey engine executes the injected function in the reduce context, granting access to all matching document values. The injected code persists in the design document and executes on every subsequent view query. CouchDB's JavaScript sandbox prevents filesystem/network access, limiting scope to data exfiltration within the database. The fix (available in version 3.38.1) adds allowlist validation and request body schema validation to the V1 route.
Affected products
- Budibase @budibase/server < 3.38.1
Timeline
- 2026-05-18: disclosed: GHSA-363w-hvwh-w7m6 published
- 2026-05-12: patched: Fix released in version 3.38.1