
Cloud Vulnerability DB
A community-led vulnerabilities database
A critical vulnerability (GHSA-4g2x-vq5p-5vj6) was discovered in Budibase versions prior to 2.20.0, affecting the server-side code execution functionality. The vulnerability stems from the use of the vm2 library for code execution inside the Budibase builder and apps, particularly in environments that executed code server-side such as automations and column formulas (GitHub Advisory).
The vulnerability is rated as Critical with a CVSS score of 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The issue allows users to escape the sandbox provided by vm2 and expose server-side variables such as process.env. The vulnerability is related to a Promise handler sanitization bypass in vm2 versions up to 3.9.19, which enables attackers to escape the sandbox and execute arbitrary code (VM2 Advisory).
The vulnerability allows attackers to escape the sandbox environment and potentially execute arbitrary code on the server side. This could lead to unauthorized access to server-side variables and potential remote code execution, affecting the confidentiality, integrity, and availability of the system (GitHub Advisory).
The vulnerability can be exploited through server-side code execution features, particularly in automations and column formulas. A proof of concept exists demonstrating the sandbox escape capability (VM2 Advisory).
The vulnerability has been patched in Budibase version 2.20.0 by migrating the entire JS sandbox infrastructure to isolated-vm, a more secure library for remote code execution. The Budibase cloud platform has been patched, but self-hosted users must upgrade to version 2.20.0 or later to address the vulnerability. There are no workarounds available; full migration to post-version 2.20.0 is required (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."