{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/budibase-3.41.0---3.44.x/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:budibase:budibase:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-100680"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Budibase (\u003c 3.45.0)","Budibase (3.41.0 - 3.44.x)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","web-application","data-exfiltration","sql-injection","cve","authentication-bypass","sso","identity-management","idor","broken-access-control","web-security","privilege-escalation","cve-2026-100686"],"_cs_type":"advisory","_cs_vendors":["Budibase"],"content_html":"\u003cp\u003eBudibase versions prior to 3.45.0 suffer from an arbitrary file read vulnerability located in the OpenAPI/Swagger import validation functionality. The issue arises because the application fails to restrict external JSON reference resolution during the import process. An attacker possessing authenticated access as a builder can exploit this misconfiguration by submitting a crafted OpenAPI specification file containing malicious file:// URI references.\u003c/p\u003e\n\u003cp\u003eWhen the application processes the imported specification, the underlying JSON parser attempts to resolve these external references against the host filesystem. This enables an attacker to read sensitive local files, such as environment variables, which often contain critical secrets like JWT signing keys, database credentials, and third-party API keys. Successful exploitation leads to significant security impact, including potential full system compromise, escalation of privilege, or unauthorized data access, given the sensitivity of configuration data stored in environment files.\u003c/p\u003e\n","date_modified":"2026-09-26T15:12:21Z","date_published":"2026-09-26T15:10:36Z","id":"https://feed.craftedsignal.io/briefs/2026-09-budibase-file-read/","summary":"Budibase versions prior to 3.45.0 contain an arbitrary file read vulnerability caused by enabled external JSON reference resolution during OpenAPI/Swagger file imports.","title":"Arbitrary File Read in Budibase OpenAPI Import Validator","url":"https://feed.craftedsignal.io/briefs/2026-09-budibase-file-read/"}],"language":"en","title":"CraftedSignal Threat Feed - Budibase (3.41.0 - 3.44.x)","version":"https://jsonfeed.org/version/1.1"}