VULNRABLE / Vulnerability / GHSA-pmpg-2mxq-6xwr

GHSA-pmpg-2mxq-6xwr

HIGH LOW @budibase/server GHSA

Exploit verdict: No active-exploit signal

CVSS Score
8
Severity
HIGH
EPSS
Source
GHSA

Summary

Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete

What this means

GHSA-pmpg-2mxq-6xwr is a high-severity vulnerability affecting @budibase/server, rated CVSS 8. Published July 25, 2026.

View full advisory at GHSA →