Hugo | DevOps | Cybersecurity 🇱🇻[verified]@HugoValtersDisclosure
The tweet announces a critical path‑traversal vulnerability (CVE‑2026‑54352) in Budibase, describing how symlink extraction allows arbitrary file reads and recommends limiting builder access before patches are released.
Joey Romaine 🇺🇸 |=★=|[verified]@Tank23x0Disclosure
The post announces CVE‑2026‑54352 for Budibase, describing a critical arbitrary file‑read flaw via symlink upload, without mentioning exploitation, patches, or active attacks.
DFIR Lab[verified]@DFIR_LabPatch
The tweet announces a critical path‑traversal vulnerability (CVE-2026-54352) in Budibase and urges users to patch to 3.39.9.
Vulmon Vulnerability Feed@VulmonFeedsGeneral
The post merely lists the CVE with a headline and a reference link, offering no detailed exploitation info or remediation steps.
CVE@CVEnewPatch
CVE-2026-54352 affects Budibase via a vulnerable POST endpoint before version 3.39.9, and the issue is addressed in that subsequent version.
Infoflowcloud@infoflowcloudGeneral
A new CVE (CVE‑2026‑54352) affecting Budibase’s API upload endpoint is reported, with a link to the CVE record, but no exploit details, patches, or active exploitation claims are provided.