CVE-2026-25041 | budibase up to 3.23.22 postgres.ts Password os command injection (GHSA-726g-59wr-cj4c / WID-SEC-2026-0651)
A vulnerability was found in budibase up to 3.23.22 and classified as critical. The affected element is an unknown function of the file packages/server/src/integrations/postgres.ts. Such manipulation of the argument Password leads to os command injection.
This vulnerability is referenced as CVE-2026-25041. It is possible to launch the attack remotely. No exploit is available.
A patch should be applied to remediate this issue.