{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/budibase-before-3.40.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-73617"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Budibase","Budibase (before 3.40.0)"],"_cs_severities":["high"],"_cs_tags":["ssrf","web-vulnerability","budibase","web-application","privilege-escalation","auth-bypass"],"_cs_type":"advisory","_cs_vendors":["Budibase"],"content_html":"\u003cp\u003eBudibase versions prior to 3.40.0 contain a critical NoSQL injection vulnerability within the MongoDB datasource integration. The vulnerability stems from the application's processing of user-supplied parameters using Handlebars with the 'noEscaping: true' setting enabled, combined with a lack of robust operator filtering.\u003c/p\u003e\n\u003cp\u003eThis flaw allows an attacker to inject MongoDB-specific operators directly into query parameters. Because the input is not sanitized or restricted, an attacker can manipulate database queries to bypass existing row-level or per-user access controls. The impact is severe, enabling unauthorized read access to arbitrary documents, potential modification or deletion of collection data, and the execution of server-side JavaScript through operators such as '$where'. This vulnerability is particularly dangerous in environments where the Budibase backend connects to MongoDB databases containing sensitive business logic or user data.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows attackers to bypass application-level access controls, leading to unauthorized data exfiltration or modification. In instances where the MongoDB instance allows the '$where' operator, attackers could escalate the impact to arbitrary code execution on the database server. This impacts all organizations using Budibase 3.39.x and earlier versions that integrate with MongoDB.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Budibase instances to version 3.40.0 or later immediately to patch CVE-2026-73617.\u003c/li\u003e\n\u003cli\u003eAudit logs for suspicious MongoDB queries involving unconventional operators (e.g., $where, $gt, $ne, $regex) originating from the Budibase application server.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation and query parameterization for any user-facing inputs bound to MongoDB datasource queries.\u003c/li\u003e\n\u003cli\u003eApply the principle of least privilege to the service account credentials used by Budibase to connect to MongoDB, restricting permissions to only those necessary for required operations.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-14T00:06:56Z","date_published":"2026-08-13T12:56:46Z","id":"https://feed.craftedsignal.io/briefs/2026-08-budibase-nosql-injection/","summary":"Budibase versions prior to 3.40.0 are vulnerable to NoSQL injection in the MongoDB datasource due to improper handling of user-supplied parameters, allowing unauthorized data access and potential server-side execution.","title":"NoSQL Injection Vulnerability in Budibase MongoDB Integration","url":"https://feed.craftedsignal.io/briefs/2026-08-budibase-nosql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Budibase (Before 3.40.0)","version":"https://jsonfeed.org/version/1.1"}