Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
📦
📦 npm
Not in CISA KEV
HIGH severity

CVE-2026-54356 — @budibase/server

HIGH

CVE-2026-54356 is a high-severity (CVSS 7.1) CWE-862 vulnerability in @budibase/server. No vendor fix is recorded yet; mitigation options are listed below.

Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url`

Also known asGHSA-6x9p-4r67-5gjx
Published
Aug 17, 2026
Updated
Sep 10, 2026
Affected
1 pkg
Patched
None yet
Exploits
None indexed
Exploitation data as of Oct 1, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Exploitation Status

Proof-of-concept exploit code exists

  • CISA’s SSVC triage found public proof-of-concept exploit code for this CVE, though no confirmed active exploitation.

Exploitation and automatability from CISA’s SSVC triage for CVE-2026-54356.

EPSS Exploitation Probability

via FIRST.org ↗
0.4%probability of exploitation in next 30 days
Lower Risk+0.11%
Lower risk than most CVEs26th percentile — riskier than 26% of all scored CVEsHighest risk
0.00%0.28%0.57%0.85%0.2%0.4%Sep 26Oct 26

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

How urgent is this, really

CVE-2026-54356 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.

Where this sits among everything scored

Of 381,682 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.

Real-World Exposure

1 pkg affected

How broadly this vulnerability is actually deployed: weekly install volume shows current usage, and reverse-dependency count shows how many other packages break if it stays unpatched.

1other npm packages depend on this — each one inherits the vulnerability until it's patched upstream
@budibase/servernpm
30Kdownloads / week

Description

Summary

Budibase 3.39.7 allows a low-privilege authenticated published-app user with the built-in BASIC role to obtain arbitrary S3 pre-signed upload URLs backed by a workspace datasource's stored server-side credentials.

The affected endpoint is:

POST /api/attachments/:datasourceId/url

The caller can control:

bucket
key

and receives:

signedUrl
publicUrl

This lets a low-privilege published-app user mint S3 PUT URLs using server-side datasource credentials for attacker-chosen object destinations.

Steps:

  1. Log in as an admin user.
  2. Create a new app/workspace.
  3. In the development app context, create an S3 datasource with valid credentials.
  4. Publish the app.
  5. Create a low-privilege user with the built-in BASIC role on the published production app ID.
  6. Log in as that BASIC user.
  7. Send: POST /api/attachments/<datasourceId>/url

with:

{"bucket":"foo","key":"bar"}

and the published app header:

x-budibase-app-id: <published_app_id>

Observe a successful response containing:

signedUrl
publicUrl

Observed result

The following behavior:

dev BASIC request: 403 User does not have permission app publish: SUCCESS prod BASIC request: 200 OK Example confirmed runtime values from the final successful run:

prodAppId: app_e6b4cdc6cd6949969a83ff11eee88c5a
datasourceId: datasource_0cec491b26a742468257c62382aa3284
publicUrl: https://foo.s3.eu-west-1.amazonaws.com/bar

The returned signedUrl contained standard AWS signing markers, including:

X-Amz-Credential=bb
X-Amz-Signature
X-Amz-Expires=900

Impact

A low-privilege published-app user who knows a valid datasource ID can mint S3 upload URLs backed by server-side datasource credentials and choose arbitrary destination bucket and key values.

Route definition

packages/server/src/api/routes/static.ts:45 Authorization logic packages/server/src/middleware/authorized.ts packages/server/src/middleware/resourceId.ts Controller logic packages/server/src/api/controllers/static/index.ts Datasource lookup packages/server/src/sdk/workspace/datasources/datasources.ts

Affected Packages

1 total
EcosystemPackageVulnerable rangeFix
📦npm@budibase/serverall versionsNo fix

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for @budibase/server, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Remediation status

    No patched version of @budibase/server has shipped for CVE-2026-54356 yet. Where your build allows, override or pin the dependency away from the vulnerable range, and apply any maintainer-recommended mitigation.

  3. Mitigate without a patch

    Put an independent control in front of the weakness: restrict the affected endpoint or interface to trusted networks, require an additional authentication factor or proxy-level check, and invalidate existing sessions and credentials in case the flaw has already been used.

Frequently Asked Questions

### Summary Budibase 3.39.7 allows a low-privilege authenticated published-app user with the built-in BASIC role to obtain arbitrary S3 pre-signed upload URLs backed by a workspace datasource's stored server-side credentials. The affected endpoint is: `POST /api/attachments/:datasourceId/url` The caller can control: ```text bucket key ``` and receives: ```text signedUrl publicUrl ``` This lets a low-privilege published-app user mint S3 `PUT` URLs using server-side datasource credentials for attacker-chosen object destinations. Steps: 1. Log in as an admin user. 2. Create a new app/worksp
O3 Security · Impact-Aware SCA

Is CVE-2026-54356 in your dependencies?

Find it across npm, including transitive dependencies.

CVE-2026-54356: @budibase/server (High 7.1) | O3 Security