Vulnerability DatabaseGHSA-4g2x-vq5p-5vj6

GHSA-4g2x-vq5p-5vj6
JavaScript vulnerability analysis and mitigation

Overview

A critical vulnerability (GHSA-4g2x-vq5p-5vj6) was discovered in Budibase versions prior to 2.20.0, affecting the server-side code execution functionality. The vulnerability stems from the use of the vm2 library for code execution inside the Budibase builder and apps, particularly in environments that executed code server-side such as automations and column formulas (GitHub Advisory).

Technical details

The vulnerability is rated as Critical with a CVSS score of 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The issue allows users to escape the sandbox provided by vm2 and expose server-side variables such as process.env. The vulnerability is related to a Promise handler sanitization bypass in vm2 versions up to 3.9.19, which enables attackers to escape the sandbox and execute arbitrary code (VM2 Advisory).

Impact

The vulnerability allows attackers to escape the sandbox environment and potentially execute arbitrary code on the server side. This could lead to unauthorized access to server-side variables and potential remote code execution, affecting the confidentiality, integrity, and availability of the system (GitHub Advisory).

Exploitability

The vulnerability can be exploited through server-side code execution features, particularly in automations and column formulas. A proof of concept exists demonstrating the sandbox escape capability (VM2 Advisory).

Mitigation and workarounds

The vulnerability has been patched in Budibase version 2.20.0 by migrating the entire JS sandbox infrastructure to isolated-vm, a more secure library for remote code execution. The Budibase cloud platform has been patched, but self-hosted users must upgrade to version 2.20.0 or later to address the vulnerability. There are no workarounds available; full migration to post-version 2.20.0 is required (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-54504HIGH8.8
  • JavaScript logoJavaScript
  • @andrea9293/mcp-documentation-server
NoYesSep 17, 2026
CVE-2026-77615HIGH8.7
  • JavaScript logoJavaScript
  • paella-core
NoYesSep 17, 2026
CVE-2026-91127HIGH8.2
  • JavaScript logoJavaScript
  • @file-viewer/doc
NoYesSep 18, 2026
CVE-2026-77301HIGH7.5
  • JavaScript logoJavaScript
  • adm-zip
NoYesSep 18, 2026
CVE-2026-84992MEDIUM6.1
  • JavaScript logoJavaScript
  • md-editor-v3
NoYesSep 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management