Security Advisory

CVE-2026-73409

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-12 19:19:59
Last updated 2026-08-14 22:09:19
Assigner GitHub_M
CVSS score not scored
State PUBLISHED

Description

Budibase is an open-source low-code platform. Prior to 3.40.1, packages/server/src/integrations/mongodb.ts passed builder-controlled tlsCertificateKeyFile and tlsCAFile values directly to MongoClient on Budibase Cloud. A builder could submit absolute server paths through /api/datasources/verify and distinguish readable existing files from missing files by comparing the driver error, exposing a filesystem existence and readability oracle on the shared server. This issue is fixed in version 3.40.1.