CVE-2026-54350 is a critical injection flaw in Budibase affecting versions prior to 3.39.12. In published applications, Budibase allows execution of PUBLIC queries through POST /api/v2/queries/:queryId without a session, requiring only the publicly exposed x-budibase-app-id header. The vulnerable path substitutes user-supplied parameter values into raw JSON query bodies in enrichContext (packages/server/src/sdk/workspace/queries/queries.ts:121-138) and then parses the resulting string with JSON.parse. Input validation in validateQueryInputs (packages/server/src/api/controllers/query/index.ts:61-71) blocks only Handlebars markers and does not escape JSON metacharacters such as quotes, backslashes, or closing braces. As a result, an attacker can inject crafted values that break out of the intended JSON value and introduce attacker-controlled keys or operators into the parsed query object. For MongoDB find operations, the manipulated filter is passed directly to collection.find() (packages/server/src/integrations/mongodb.ts:506-510), enabling duplicate-key override patterns such as replacing a builder-defined constraint like {name:"..."} with an attacker-controlled condition like {name:{$exists:true}} to return all documents. The same primitive can target updateMany operations (mongodb.ts:577-585), broadening the filter to the full collection while preserving the builder-defined update body. The issue also affects other JSON-based backends exposed through PUBLIC queries, including CouchDB, Elasticsearch, DynamoDB-PartiQL, and REST-with-JSON-body integrations.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a working Python PoC for CVE-2026-54350, an unauthenticated NoSQL/JSON operator injection in Budibase PUBLIC queries. The main exploit file is exploit.py, which sends a POST request to /api/v2/queries/<queryId> with a JSON body containing attacker-controlled parameters and the public x-budibase-app-id header. The injected parameter closes a JSON string in the server-side query template and inserts a duplicate field using a MongoDB operator object ({"$exists":true}), causing the parsed query filter to match all documents. In write mode, the same primitive can widen an updateMany filter and mass-modify records. Repository structure: exploit.py is the standalone exploit using only Python standard library modules. ANALYSIS.md and README.md document root cause, affected versions, exploitability boundary, and usage. The lab/ directory contains a full reproduction environment: setup.sh launches Budibase 3.39.0 and MongoDB 4.4 in Docker; seed.js populates a synthetic customers collection; provision.py uses legitimate Budibase builder APIs to create an app, datasource, read and update queries, mark them PUBLIC, and publish the app. Capabilities: unauthenticated data extraction from PUBLIC read queries and unauthenticated mass update through PUBLIC write queries. The exploit is not merely a detector; it actively triggers the vulnerable endpoint and parses returned data. It is operational but basic, with a hardcoded injection strategy centered on MongoDB-style operators and Budibase query execution semantics.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.