# sonatype-2026-005082

@budibase/server - SQL Injection

Published Jul 25, 2026

[Advisory · GHSA-pmpg-2mxq-6xwr](https://github.com/advisories/GHSA-pmpg-2mxq-6xwr)

## Security Details

### Components Impacted

- Sonatype Research

### sonatype-2026-005082 Security Details

- **CVE ID**: sonatype-2026-005082
- **CWE**: N/A
- **CVE Description**: @budibase/server - SQL Injection
- **Published**: Jul 25, 2026
- **CVSS Score & Severity**: 7.1 High
- **CVSS Vector**: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
- **EPSS Score**: 0%
- **Malware**: malware
- **KEV Status**: Not in KEV Catalog: No known exploits
- **Affected Ecosystems**: affected
- **Source**: Sonatype

### References

[GitHub · Advisory · GHSA-pmpg-2mxq-6xwr](https://github.com/advisories/GHSA-pmpg-2mxq-6xwr "https://github.com/advisories/GHSA-pmpg-2mxq-6xwr")
