THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-6x9p-4r67-5gjx (high) — Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url`

[GHSA] GHSA-6x9p-4r67-5gjx (high) — Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url`

medgithub_advisoriesPublished 2026-08-26

GHSA-6x9p-4r67-5gjx Severity: high CVE: CVE-2026-54356

Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url`

### Summary Budibase 3.39.7 allows a low-privilege authenticated published-app user with the built-in BASIC role to obtain arbitrary S3 pre-signed upload URLs backed by a workspace datasource's stored server-side credentials.

The affected

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-6x9p-4r67-5gjx