Vulnerabilities/

Budibase affected by VM2 Constructor Escape Vulnerability

Severity:
High

Description

Previously, budibase used a library called vm2 for code execution inside the Budibase builder and apps, such as the UI below for configuring bindings in the design section.

Recommendation

Update the @budibase/server package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@budibase/server
Anything's wrong? Let us know Last updated on March 01, 2024

This issue is available in SmartScanner Professional

See Pricing