HIGH
Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile
Published Aug 12, 2026
7.0
HIGHCVSS 4.0
EPSS 0.32%
Description
Budibase is an open-source low-code platform. Prior to 3.40.1, packages/server/src/integrations/mongodb.ts passed builder-controlled tlsCertificateKeyFile and tlsCAFile values directly to MongoClient on Budibase Cloud. A builder could submit absolute server paths through /api/datasources/verify and distinguish readable existing files from missing files by comparing the driver error, exposing a filesystem existence and readability oracle on the shared server. This issue is fixed in version 3.40.1.
Affected products
-
Affected
- < 3.40.1
No data.
No data.
No Red Hat product state for this CVE.
@budibase/server
npm
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @budibase/server | 0 | not fixed |
Remediation
No remediation recorded yet.
References (8)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-57509 Advisory
- https://github.com/Budibase/budibase/commit/5e19b935536d6d1be1f47100e43c6fb30917826e
- https://github.com/Budibase/budibase/commit/e58aa31e18272f6a1a8aeb525b7eef0b01b1dd43 x_refsource_MISC
- https://github.com/Budibase/budibase/pull/19244 x_refsource_MISC
- https://github.com/Budibase/budibase/releases/tag/3.40.0
- https://github.com/Budibase/budibase/releases/tag/3.40.1 x_refsource_MISC
- https://github.com/Budibase/budibase/security/advisories/GHSA-ppr4-5f46-j9c6 patchx_refsource_CONFIRM
- https://github.com/advisories/GHSA-ppr4-5f46-j9c6 Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 12, 2026
Updated Aug 14, 2026
Reserved Aug 12, 2026
Link CVE-2026-73409
CISA Vulnrichment
Updated Aug 14, 2026
Red Hat
No data
GitHub
Link GHSA-PPR4-5F46-J9C6