Known Vulnerabilities for App-builder-lib by Electron-userland
Listed below are 10 of the newest known vulnerabilities associated with "App-builder-lib" by "Electron-userland".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-73409 json | Budibase is an open-source low-code platform. Prior to 3.40.1, packages/server/src/integrations/mongodb.ts passed builder-con... | Not Provided | 2026-08-12 | 2026-08-12 |
| CVE-2026-73308 json | Budibase is an open-source low-code platform. Prior to 3.39.25, packages/server/src/api/controllers/automation.ts returned au... | Not Provided | 2026-08-12 | 2026-08-12 |
| CVE-2026-73307 json | Budibase is an open-source low-code platform. Prior to 3.39.4, uploadUrl in packages/server/src/utilities/fileUtils.ts used a... | Not Provided | 2026-08-12 | 2026-08-12 |
| CVE-2026-73305 json | Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRoleUpd... | Not Provided | 2026-08-13 | 2026-08-13 |
| CVE-2026-73301 json | Budibase is an open-source low-code platform. Prior to 3.39.25, the GET /api/global/groups endpoint in packages/worker/src/ap... | Not Provided | 2026-08-12 | 2026-08-12 |
| CVE-2026-73140 json | Affected versions of cti-transmute fail to apply comment-level access-control rules when generating evaluation report exports... | Not Provided | 2026-08-11 | 2026-08-11 |
| CVE-2026-72855 json | Budibase before 3.40.0 contains server-side request forgery vulnerabilities in OpenAPI query import and REST query execution ... | Not Provided | 2026-08-13 | 2026-08-13 |
| CVE-2026-72851 json | Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_... | Not Provided | 2026-08-13 | 2026-08-13 |
| CVE-2026-72681 json | Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana fe... | Not Provided | 2026-08-13 | 2026-08-13 |
| CVE-2026-72680 json | Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier of a stored conversation from a user-supplied input, an... | Not Provided | 2026-08-13 | 2026-08-13 |