Sploitus

CVE-2026-35214

No indexed exploits for CVE-2026-35214 yet

Budibase is an open-source low-code platform. Prior to version 3.33.4, the plugin file upload endpoint (POST /api/plugin/upload) passes the user-supplied filename directly to createTempFolder() without sanitizing path traversal sequences. An attacker with Global Builder privileges can craft a multipart upload with a filename containing ../ to delete arbitrary directories via rmSync and write arbitrary files via tarball extraction to any filesystem path the Node.js process can access. This issue has been patched in version 3.33.4.

Affected products
Budibase
Budibase
< 3.33.4
Fix
Available
CVSS 3.1
8.7 HIGH
EPSS
0.6% (44th percentile)
Weakness
CWE-22
NVD status
Analyzed
Published
2026-04-03
CVE-2026-35214 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-35214 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-35214 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.