oM noM Security Feeds cve
vulnerability context

CVE-2026-54352

CVSS 9.6 CRITICALEPSS 37%CWE-22OTX 1 pulse

Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at packages/server/src/api/routes/static.ts:24 accepts a builder-uploaded .zip, extracts it with [email protected] into a temp directory, then for each entry listed in icons.json validates the icon path, opens it, and streams the bytes into MinIO. The resulting object is served back via GET /api/assets/{appId}/pwa/{uuid}.png. [email protected] preserves absolute symlink targets when restoring symlink entries. The icon-source validator at packages/server/src/api/controllers/static/index.ts:259-268 resolve...

Published 2026-06-26 · last modified 2026-06-27

details

CISA KEV status
Not in catalog
CVSS v3
9.6 / CRITICAL
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
EPSS
37% percentile (score 0.0047)
CWE
CWE-22
OTX pulses
1 total, 0 recent

source mentions 2

source consensus

  • Bluesky
  • GitHub Advisories
Want the 3-bullet summary of CVE-2026-54352, plus webhook alerts when KEV is updated? Pro is $10/mo.