Executive brief
Budibase, a low-code application platform, fails to properly sanitize filenames when storing user uploads in its S3 object storage. An authenticated builder can craft specially crafted filenames with path traversal sequences (e.g., `../../../`) that escape the intended directory structure during workspace export, enabling arbitrary file writes to any location on the server filesystem where the Budibase process has write permissions. This allows an attacker to plant malicious files in system directories or configuration folders, potentially leading to remote code execution or service compromise.
Technical details
This vulnerability is a path traversal flaw affecting Budibase's S3 object storage handling. The root cause spans two issues: (1) the `sanitizeKey` function uses the outdated `sanitize-s3-objectkey@0.0.1` library which fails to neutralize `..` segments in filenames—it only strips "unsafe" punctuation while preserving forward slashes and dots; (2) the `retrieveDirectory` function during workspace export writes S3 object contents to the local filesystem via `path.join()` without validating that the resolved path remains within the intended temporary directory. An authenticated builder can upload a file (via AI knowledge base upload or admin global config upload endpoints) with a crafted key like `app_prod_x/ai/knowledge-bases/kb_x/files/f_x/../../../../etc/cron.d/evil`. When the workspace is later exported, `retrieveDirectory` lists all objects under the workspace prefix and writes each to disk; Node's `path.join()` resolves the `..` segments, allowing the file body to be written outside the temporary directory to paths like `/etc/cron.d/` or `~/.ssh/`. The attack requires builder-level or admin authentication and is triggered during the export operation, but the initial malicious file upload is reachable via standard HTTP APIs. Patched in version 3.40.0.
Affected products
- Budibase Budibase before 3.40.0
Timeline
- 2026-07-22: disclosed: GitHub Security Advisory published
- 2026-08-13: patched: Fix released in version 3.40.0
- 2026-08-13: advisory: CVE-2026-72850 published