VYPR

@budibase/server

by Budibase

Source repositories

CVEs (1)

  • CVE-2026-100684HigSep 26, 2026
    risk 0.46cvss 8.1epss —

    Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server. In sso.authenticate, when no existing user matches the incoming SSO subject, the server looks up pending user invites by the IdP-asserted email address alone…