Executive brief
Budibase is a low-code platform that allows builders to create applications with database queries, including MongoDB connectivity. A NoSQL injection vulnerability in the MongoDB datasource lets any basic-level app user bypass query-level access controls set by the application builder, allowing them to read all documents in connected MongoDB collections regardless of intended row-level restrictions. This breaks data isolation and can expose sensitive information across the entire database.
Technical details
The vulnerability is a NoSQL injection in Budibase's MongoDB query processing. Builders use Handlebars templating with bindings (e.g., {"email": "{{ currentUser.email }}"}) to scope queries per-user; the Handlebars enrichment uses noEscaping: true, then passes the result to JSON.parse. An attacker injects MongoDB operators using a duplicate-key technique (e.g., x", "name": {"$ne": "x"}, "$comment": "payload) that JSON.parse resolves to an operator-based filter. Unlike SQL datasources, which parameterize bindings through interpolateSQL(), the MongoDB path has no equivalent parameterization, allowing injected operators to reach collection.find() unchanged. Any BASIC app user with query execution permission can exploit this to dump collections, execute arbitrary MongoDB operations, or access cross-collection data.
Affected products
- Budibase Budibase <3.40.0
Timeline
- 2026-07-24: disclosed
- 2026-07-24: patched: Version 3.40.0 released