Executive brief
Budibase is an open-source platform used to build internal business applications. A security flaw in how the platform handles text formatting allows users with basic write access to inject malicious scripts into application screens. When an administrator or another user views this content, the script can execute in their session, potentially allowing the attacker to steal sensitive session data, access private records, or perform actions on behalf of the administrator.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the Budibase Text component due to the unsafe use of 'innerHTML' when rendering Markdown. The 'MarkdownViewer.svelte' component processes user-supplied input using 'marked.parse()' without subsequent sanitization, allowing arbitrary HTML tags to be injected. An attacker with 'BASIC' user permissions and write access to a table can inject malicious payloads, such as iframes with 'srcdoc' attributes. On Budibase Cloud, attackers can bypass Content Security Policy (CSP) by uploading malicious '.mjs' files as attachments to a trusted CloudFront origin. In self-hosted environments, the lack of file extension validation for non-public users allows the upload of '.html' files that execute in the app's origin. These vectors allow for session hijacking and unauthorized API interaction. The issue is resolved in version 3.39.0.
Affected products
- Budibase Budibase < 3.39.0
Timeline
- 2026-05-21: advisory: GitHub Security Advisory published
- 2026-05-27: disclosed: NVD publication date