
CVE-2026-42239 Budibase is an open-source low-code platform. Prior to version 3.35.10, the budibase:auth cookie containing the JWT session token is set with httpOnly: false at packa… https://www.cve.org/CVERecord?id=CVE-2026-42239
Post summary
Budibase’s low‑code platform has a cookie‑related security flaw (httpOnly: false) affecting versions before 3.35.10, as documented in CVE-2026-42239. No PoC, exploit, or active exploitation is reported, but upgrading to 3.35.10 mitigates the issue.

