All verified exploits

CVE-2026-35216 Unauthenticated Remote Code Execution via Webhook Command Injection

Deterministic critical Budibase Added cve-verified-cve-2026-35216

Detects Budibase instances running version 3.33.3 or earlier. The webhook trigger endpoint (/api/webhooks/trigger/) requires no authentication, and the bash automation step passes user-controlled payload data through Handlebars template processing directly into Node.js execSync() without sanitisation. An attacker can inject arbitrary OS commands via webhook payload fields, executing as root inside the container. The fix in 3.33.4 replaces execSync with execa (no shell) and splits the freeform code field into separate command + args.

Related Budibase exploits

Is your app exploitable through CVE-2026-35216?

Scan your domain free