SCA: security update for budibase (GHSA-rvhr-26g4-p2r8)

critical Tenable Cloud Security Plugin ID 438091

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Budibase is a low code platform for creating internal tools, workflows, and admin panels. Prior to version
3.30.4, an unsafe `eval()` vulnerability in Budibase's view filtering implementation allows any
authenticated user (including free tier accounts) to execute arbitrary JavaScript code on the server. This
vulnerability ONLY affects Budibase Cloud (SaaS) - self-hosted deployments use native CouchDB views and
are not vulnerable. The vulnerability exists in `packages/server/src/db/inMemoryView.ts` where user-
controlled view map functions are directly evaluated without sanitization. The primary impact comes from
what lives inside the pod's environment: the `app-service` pod runs with secrets baked into its
environment variables, including `INTERNAL_API_KEY`, `JWT_SECRET`, CouchDB admin credentials, AWS keys,
and more. Using the extracted CouchDB credentials, we verified direct database access, enumerated all
tenant databases, and confirmed that user records (email addresses) are readable. Version 3.30.4 contains
a patch. (CVE-2026-27702)

See Also

https://github.com/advisories/GHSA-rvhr-26g4-p2r8

Plugin Details

Severity: Critical

ID: 438091

Version: Revision 1.4

Type: Local

Family: SCA Checks

Published: 3/3/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 94.39

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 7

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-27702

CVSS v3

Risk Factor: Critical

Base Score: 9

Temporal Score: 8.1

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2/25/2026

Vulnerability Publication Date: 2/25/2026

Reference Information

CVE: CVE-2026-27702