{"id":"CVE-2026-100682","published":"2026-09-26T14:16:52.433","lastModified":"2026-09-28T16:36:05.010","description":"Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon upload endpoint that extracts user-supplied ZIP archives without proper symlink validation. Attackers with BUILDER role can craft a malicious ZIP with leaf symlink entries followed by duplicate file entries to write arbitrary files as root, enabling remote code execution.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-22"],"vendors":[],"products":[],"references":[{"url":"https://github.com/Budibase/budibase/security/advisories/GHSA-37r6-5jxh-vm83","tags":[]},{"url":"https://www.vulncheck.com/advisories/budibase-server-before-3.45.0-arbitrary-file-write-via-zip-symlink","tags":[]}],"exploitRefs":[{"url":"https://github.com/Budibase/budibase/security/advisories/GHSA-37r6-5jxh-vm83","tags":[]}],"hasPoc":true,"ai":{"summary":"This vulnerability allows attackers with BUILDER role to write arbitrary files as root via a malicious ZIP archive, enabling remote code execution.","exploitability":"Exploitation requires an attacker to have BUILDER role and craft a specific ZIP archive, making it moderately hard to exploit.","blast_radius":"If exploited, this could lead to full control of the server, including remote code execution, with severe consequences.","remediation":"Upgrade to Budibase Server 3.45.0 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","web","arbitrary-file-write"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T09:03:43.791Z"}}