CVE-2026-73409
Gravedad CVSS v4.0:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
12/08/2026
Última modificación:
08/09/2026
Descripción
*** Pendiente de traducción *** Budibase is an open-source low-code platform. Prior to 3.40.1, packages/server/src/integrations/mongodb.ts passed builder-controlled tlsCertificateKeyFile and tlsCAFile values directly to MongoClient on Budibase Cloud. A builder could submit absolute server paths through /api/datasources/verify and distinguish readable existing files from missing files by comparing the driver error, exposing a filesystem existence and readability oracle on the shared server. This issue is fixed in version 3.40.1.
Impacto
Puntuación base 4.0
5.10
Gravedad 4.0
MEDIA
Referencias a soluciones, herramientas e información
- https://github.com/Budibase/budibase/commit/e58aa31e18272f6a1a8aeb525b7eef0b01b1dd43
- https://github.com/Budibase/budibase/pull/19244
- https://github.com/Budibase/budibase/releases/tag/3.40.1
- https://github.com/Budibase/budibase/security/advisories/GHSA-ppr4-5f46-j9c6
- https://github.com/Budibase/budibase/security/advisories/GHSA-ppr4-5f46-j9c6


