# sonatype-2026-005077

@budibase/server - Time-of-check Time-of-use (TOCTOU) Race Condition

Published Jul 25, 2026

[Advisory · GHSA-v42f-v8xc-j435](https://github.com/advisories/GHSA-v42f-v8xc-j435)

**CVSS Score**: High 8.5

## Security Details

### Components Impacted

Sonatype Research

### sonatype-2026-005077 Security Details

**CVE ID**: sonatype-2026-005077  
**CVE Description**: @budibase/server - Time-of-check Time-of-use (TOCTOU) Race Condition  
**Published**: Jul 25, 2026  
**CVSS Score & Severity**: 8.5 High  
**CVSS Vector**: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H  
**EPSS Score**: 0%  
**Malware**: malware  
**KEV Status**: Not in KEV Catalog: No known exploits

### Affected Ecosystems

Source: Sonatype

### References

[GitHub · Advisory · GHSA-v42f-v8xc-j435](https://github.com/advisories/GHSA-v42f-v8xc-j435 "https://github.com/advisories/GHSA-v42f-v8xc-j435")
