🚨 CVE-2026-100683

CVENOTIFYneutralcyber2026-09-28 16:52:54 UTC
AdYour ad here[email protected]

🚨 CVE-2026-100683 Budibase (@budibase/server) before 3.45.0 builds MySQL and MSSQL column-rename DDL in packages/backend-core/src/sql/sqlTable.ts by interpolating identifiers directly into a raw query string (backtick-quoted for MySQL, a single-quoted sp_rename literal for MSSQL) without applying the project's quoteMySqlIdentifier / quoteSqlServerIdentifier helpers. An attacker with DDL rights on a connected MySQL/MSSQL datasource can create a column whose name contains a backtick (MySQL) or…

Read the full story at cvenotify ↗
AdYour ad here[email protected]