Morty[verified]@MortyJinExploit
The post offers a technical analysis of CVE‑2026‑31816, revealing a regex flaw that can bypass authentication and lead to RCE, includes a PoC repository, and cites a security advisory with patch details.
Chris[verified]@theshodandorkDisclosure
The text discloses technical details of two CVEs in Budibase: CVE-2026-31816 enables auth bypass by appending a specific query string, while CVE-2026-30240 uses path traversal in crafted ZIP files to read sensitive environment data. No proof of concept, exploit code, patch, or active exploitation is reported.
Gray Hats@the_yellow_fallPatch
The tweet alerts that two critical Budibase CVEs enable unauthenticated API access and path traversal for secret exfiltration, urging immediate patching.
pdnuclei-bot@pdnuclei_botDisclosure
Budibase versions up to 3.31.4 suffer a critical authentication bypass via an unanchored regex; the vulnerability is disclosed with technical details and a reference link, but no exploitable code, active exploitation, or patch is announced.
CVEFind.com@CveFindComDisclosure
Budibase low‑code platform (v3.31.4 and earlier) has a critical vulnerability that allows unauthenticated remote attackers to bypass API endpoint protection via a webhook payload. No PoC, exploit code, patch, or active exploitation details are provided.
CVE@CVEnewGeneral
The text references CVE-2026-31816 and notes affected Budibase versions, but provides no detailed technical, exploit, or mitigation information.
The Hacker Wire@TheHackerWireDisclosure
A critical CVE-2026-31816 affecting Budibase versions 3.31.4 and earlier is announced, highlighting a flaw in the authorized() middleware, but no details on PoC, exploits, patches, or active attacks are provided.