Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: true, enabling execution of multiple SQL statements in a single query. Attackers can inject malicious SQL commands through user input fields, leading to complete database compromise. This vulnerability is fixed in 3.40.0.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-12 18:18
Updated : 2026-09-08 20:56
NVD link : CVE-2026-73300
Mitre link : CVE-2026-73300
CVE.ORG link : CVE-2026-73300
JSON object : View
Products Affected
No product.
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
