Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling. The server calls eval() on plugin JavaScript files without sandboxing in the main Node.js process. This allows attackers to execute arbitrary code by uploading a malicious plugin tarball.
An authenticated admin user over the network can upload a malicious plugin tarball and execute arbitrary code with root privileges in default deployments, including exfiltrating environment variables and credentials.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
Patch available - upgrade to Budibase version 3.41.3 or later.
Upgrade Budibase to version 3.41.3 or later immediately. Restrict admin access to trusted users only. Monitor for suspicious plugin uploads and audit existing plugins for malicious content. Consider network segmentation to limit the scope of compromised instances.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Feedly found the first article mentioning CVE-2026-82244 . See article
NVD published the first details for CVE-2026-82244
A CVSS base score of 9.1 has been assigned.
GitHub Advisories released a security advisory .
A critical remote code execution vulnerability exists in Budibase versions prior to 3.41.3, with a CVSS score of 9.4, allowing authenticated admin users to upload malicious plugins and execute arbitrary code with root privileges. Currently, there is no evidence of exploitation in the wild or public proof-of-concept exploits. A patch is available by upgrading to version 3.41.3 or later, and it is recommended to restrict admin access and monitor for suspicious plugin uploads. See article
CVE-2026-82244 - Exploits & Severity - Feedly
CVE-2026-82244 - Exploits & Severity - Feedly
CVE-2026-82244: Budibase before 3.41.3 Remote Code Execution via Plugin eval() [CRITICAL] CVSS 9.4
CVE-2026-82244 | Budibase up to 3.41.2 Plugin eval code injection
Collect, analyze, and vulnerability reports faster using AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
