Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. @budibase/server
  4. ›
  5. GHSA-xcx6-4f2g-hhgx

GHSA-xcx6-4f2g-hhgx: Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLs

July 24, 2026

In Budibase v3.39.4, a regression in the authorization level for the S3 attachment upload endpoint allows any BASIC app user to obtain S3 PutObject presigned URLs. The endpoint uses TABLE/WRITE permission level instead of the intended BUILDER level defined in v3.39.3. Additionally, the controller does not pin the target bucket to the datasource’s configured bucket, allowing writes to any S3 bucket the stored IAM credentials can access.

References

  • github.com/Budibase/budibase/releases/tag/3.40.0
  • github.com/Budibase/budibase/security/advisories/GHSA-xcx6-4f2g-hhgx
  • github.com/advisories/GHSA-xcx6-4f2g-hhgx

Code Behaviors & Features

Detect and mitigate GHSA-xcx6-4f2g-hhgx with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 3.38.1

Solution

Unfortunately, there is no solution available yet.

Impact 7.7 HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N

Learn more about CVSS

Weakness

  • CWE-863: Incorrect Authorization

Source file

npm/@budibase/server/GHSA-xcx6-4f2g-hhgx.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 08 Aug 2026 00:17:30 +0000.