# sonatype-2026-005074

@budibase/server - SQL Injection

Published Jul 25, 2026

[Advisory · GHSA-q6x4-v3qx-85qw](https://github.com/advisories/GHSA-q6x4-v3qx-85qw)

## CVSS Score
Critical 9.6

### Security Details

#### Components Impacted
Sonatype Research

### sonatype-2026-005074 Security Details

- **CVE ID**: sonatype-2026-005074
- **CVE Description**: @budibase/server - SQL Injection
- **Published**: Jul 25, 2026
- **CVSS Score & Severity**: 9.6 Critical
- **CVSS Vector**: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- **EPSS Score**: 0%
- **Malware**: malware
- **KEV Status**: Not in KEV Catalog: No known exploits

### Affected Ecosystems
Source: Sonatype

### References
[GitHub · Advisory · GHSA-q6x4-v3qx-85qw](https://github.com/advisories/GHSA-q6x4-v3qx-85qw "https://github.com/advisories/GHSA-q6x4-v3qx-85qw")
