Project Subscriptions
No data.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-363w-hvwh-w7m6 | Budibase: CouchDB Reduce Injection via Unsanitized Calculation Parameter in V1 Views API |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 27 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 May 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Budibase is an open-source low-code platform. Prior to 3.38.1, the V1 Views API (POST /api/views) accepts a calculation parameter from the request body that is interpolated directly into a CouchDB reduce function definition without validation. Although an internal SCHEMA_MAP object defines the valid calculation types (sum, count, stats), no actual validation is performed against this map before the value is used in string interpolation. A user with Builder permissions can inject arbitrary JavaScript code that will be executed within the CouchDB JavaScript engine when the view is queried. This vulnerability is fixed in 3.38.1. | |
| Title | Budibase: CouchDB Reduce Injection via Unsanitized Calculation Parameter in V1 Views API | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-27T18:36:23.178Z
Reserved: 2026-05-13T05:51:48.666Z
Link: CVE-2026-45719
Updated: 2026-05-27T18:34:56.623Z
Status : Deferred
Published: 2026-05-27T18:16:26.010
Modified: 2026-05-27T20:16:39.310
Link: CVE-2026-45719
No data.
OpenCVE Enrichment
Updated: 2026-05-27T19:30:35Z
Github GHSA