Junglewise Threat Intelligence

CVE-2026-73300: Budibase SQL injection in MySQL integration via multipleStatements

CVE-2026-73300 · Severity: low · CVSS 3.1 · Published 2026-07-24

Technologies: Budibase Server, @budibase/server (npm). Vendors: Budibase, npm.

Executive brief

Budibase is a low-code application development platform that uses MySQL databases to store application data. A critical SQL injection vulnerability in its MySQL integration allows attackers to execute arbitrary SQL commands and compromise the entire database, potentially exposing or destroying customer data and disrupting business operations.

Technical details

This is a SQL injection vulnerability (CWE-89) in Budibase's MySQL integration component located in packages/server/src/integrations/mysql.ts. The root cause is the `multipleStatements: true` configuration setting in the MySQL connection, which allows multiple SQL statements to be executed in a single query. Attackers can inject malicious SQL commands through user input fields in Budibase applications. The vulnerability requires user interaction (UI:R) and is network-reachable. Exploitation enables complete database compromise including data destruction, data exfiltration, privilege escalation, and denial of service. A patch is available in version 3.40.0 that disables the `multipleStatements` setting.

Affected products

  • Budibase Budibase Server <3.40.0

Timeline

  • 2026-07-24: disclosed
  • 2026-07-24: patched: patched in version 3.40.0

References

Related threats