Product
Budibase Server versions prior to 3.45.0 allow authenticated BUILDER role users to achieve arbitrary file write and remote code execution by uploading malicious ZIP archives to the PWA icon upload endpoint.