VULNRABLE / Vulnerability / GHSA-pmpg-2mxq-6xwr
GHSA-pmpg-2mxq-6xwr
HIGH LOW @budibase/server GHSA
Exploit verdict: No active-exploit signal
CVSS Score
8
Severity
HIGH
EPSS
—
Source
GHSA
Summary
Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete
What this means
GHSA-pmpg-2mxq-6xwr is a high-severity vulnerability affecting @budibase/server, rated CVSS 8. Published July 25, 2026.
View full advisory at GHSA →