CVE-2026-100683 HIGH
← Quay lại danh sáchMô tả
Budibase (@budibase/server) before 3.45.0 builds MySQL and MSSQL column-rename DDL in packages/backend-core/src/sql/sqlTable.ts by interpolating identifiers directly into a raw query string (backtick-quoted for MySQL, a single-quoted sp_rename literal for MSSQL) without applying the project's quoteMySqlIdentifier / quoteSqlServerIdentifier helpers. An attacker with DDL rights on a connected MySQL/MSSQL datasource can create a column whose name contains a backtick (MySQL) or single quote (MSSQL) plus additional SQL; Budibase's schema introspection stores the name verbatim, and when a Budibase builder later renames that column through the UI (POST /api/tables with _rename.old), the embedded quote character terminates the identifier and the injected SQL is executed. Because the MySQL connection is opened with multipleStatements: true, stacked statements run as Budibase's datasource user, allowing arbitrary reads, writes, or destructive operations on the connected database outside Budibase's row/table permission model. Fixed in 3.45.0.
Chi tiết
| Trạng thái | Deferred |
| Điểm CVSS | 8.0 (v3.1) |
| Vector CVSS | CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H |
| Ngày công bố | 21:16 26/09/2026 |
| Ngày cập nhật | 01:17 29/09/2026 |
| Nguồn dữ liệu | nvd |
CWE
Sản phẩm bị ảnh hưởng
Nguồn dữ liệu chưa cung cấp thông tin sản phẩm chi tiết.
Tài liệu tham khảo
- [disclosure@vulncheck.com] https://github.com/Budibase/budibase/security/advisories/GHSA-ppj8-hmx2-m546
- [disclosure@vulncheck.com] https://www.vulncheck.com/advisories/budibase-before-3.45.0-sql-injection-via-column-rename-ddl
- [134c704f-9b21-4f2e-91b3-4a467353bcc0] https://github.com/Budibase/budibase/security/advisories/GHSA-ppj8-hmx2-m546
Lịch sử thay đổi
| Thời gian | Loại | Trường | Giá trị cũ | Giá trị mới |
|---|---|---|---|---|
| 01:17 29/09/2026 | MODIFIED | modified_at | 2026-09-28T16:36:05Z | 2026-09-28T18:17:15Z |
| 23:37 28/09/2026 | CREATED | cve | HIGH |