<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Budibase (3.41.0 - 3.44.x) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/budibase-3.41.0---3.44.x/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 26 Sep 2026 15:10:36 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/budibase-3.41.0---3.44.x/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Arbitrary File Read in Budibase OpenAPI Import Validator</title><link>https://feed.craftedsignal.io/briefs/2026-09-budibase-file-read/</link><pubDate>Sat, 26 Sep 2026 15:10:36 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-budibase-file-read/</guid><description>Budibase versions prior to 3.45.0 contain an arbitrary file read vulnerability caused by enabled external JSON reference resolution during OpenAPI/Swagger file imports.</description><content:encoded>&lt;p>Budibase versions prior to 3.45.0 suffer from an arbitrary file read vulnerability located in the OpenAPI/Swagger import validation functionality. The issue arises because the application fails to restrict external JSON reference resolution during the import process. An attacker possessing authenticated access as a builder can exploit this misconfiguration by submitting a crafted OpenAPI specification file containing malicious file:// URI references.&lt;/p>
&lt;p>When the application processes the imported specification, the underlying JSON parser attempts to resolve these external references against the host filesystem. This enables an attacker to read sensitive local files, such as environment variables, which often contain critical secrets like JWT signing keys, database credentials, and third-party API keys. Successful exploitation leads to significant security impact, including potential full system compromise, escalation of privilege, or unauthorized data access, given the sensitivity of configuration data stored in environment files.&lt;/p>
</content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>web-application</category><category>data-exfiltration</category><category>sql-injection</category><category>cve</category><category>authentication-bypass</category><category>sso</category><category>identity-management</category><category>idor</category><category>broken-access-control</category><category>web-security</category><category>privilege-escalation</category><category>cve-2026-100686</category></item></channel></rss>