Skip to content

budibase

v3.39.13 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ai-app-builder ai-applications crud-app crud-application data-application data-apps
+12 more
internal-tools it-workflows low-code low-code-no-code low-code-platform no-code no-code-platform rest-api-framework sql-gui workflow-apps workflow-automation workflow-engine

Affected surfaces

auth

ReleasePort's take

Moderate signal
editorial:auto 1d

Version 3.39.13 of Budibase adds IP‑based lockout to the login endpoint.

Why it matters: The new security control mitigates credential‑stuffing attacks; severity rating is 90, indicating high impact for authentication surfaces.

Summary

AI summary

IP‑based lockout added to the login endpoint.

Changes in this release

Security Critical

Adds IP-based lockout to login endpoint

Adds IP-based lockout to login endpoint

Source: llm_adapter@2026-06-11

Confidence: high

Bugfix Low

Uses app binding escaping for automations

Uses app binding escaping for automations

Source: llm_adapter@2026-06-11

Confidence: high

Bugfix Low

Clarifies menu item text

Clarifies menu item text

Source: llm_adapter@2026-06-11

Confidence: high

Full changelog

What's Changed

  • [BUDI-18938] Use app binding escaping for automations by @melohagan in https://github.com/Budibase/budibase/pull/18946
  • clarifies menu item by @mikesealey in https://github.com/Budibase/budibase/pull/18956
  • [VUL-78] Add IP-based lockout to login endpoint by @jvcalderon in https://github.com/Budibase/budibase/pull/18947

Full Changelog: https://github.com/Budibase/budibase/compare/3.39.12...3.39.13

Security Fixes

  • VUL-78 – Added IP‑based lockout to login endpoint

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track budibase

Get notified when new releases ship.

Sign up free

About budibase

AI agents that run your operations. Model agnostic.

All releases →

Beta — feedback welcome: [email protected]