Back

HIGH

Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector

Published Aug 13, 2026

Description

Budibase is an open-source low-code platform. Prior to 3.39.18, packages/server/src/integrations/mysql.ts enabled multipleStatements and inserted an unescaped tableName into a DESCRIBE statement. An attacker able to create a MySQL table with a backtick and stacked statement in its name could wait for a Budibase administrator to run schema discovery, causing the second statement to execute. The fix applies quoteMySqlIdentifier before constructing the query. This issue is fixed in version 3.39.18.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 13, 2026
Updated Aug 14, 2026
Reserved Aug 12, 2026
CISA Vulnrichment
Updated Aug 14, 2026
NVD
Status Deferred
Modified Sep 8, 2026
Red Hat
Severity n/a
Public date n/a