Skip to content

budibase

v3.39.16 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ai-app-builder ai-applications crud-app crud-application data-application data-apps
+12 more
internal-tools it-workflows low-code low-code-no-code low-code-platform no-code no-code-platform rest-api-framework sql-gui workflow-apps workflow-automation workflow-engine

Affected surfaces

auth rbac breaking_upgrade

ReleasePort's take

Moderate signal
editorial:auto 1mo

ReleasePort Layer 1 version 3.39.16 fixes broken access control on the internal table search API.

Why it matters: The fix resolves a critical (severity 90) security vulnerability affecting the internal table search surface; operators should apply this release immediately.

Summary

AI summary

[VULN-80] Fix broken access control on internal table search

Changes in this release

Security Critical

Fixes broken access control on internal table search

Fixes broken access control on internal table search

Source: llm_adapter@2026-06-15

Confidence: high

Dependency Low

Updates joi from 17.6.0 to 18.2.1 in /packages/backend-core

Updates joi from 17.6.0 to 18.2.1 in /packages/backend-core

Source: llm_adapter@2026-06-15

Confidence: high

Dependency Low

Updates esbuild from 0.18.20 to 0.28.1 across all-non-major-security group

Updates esbuild from 0.18.20 to 0.28.1 across all-non-major-security group

Source: llm_adapter@2026-06-15

Confidence: high

Full changelog

What's Changed

  • build(deps): bump joi from 17.6.0 to 18.2.1 in /packages/backend-core by @dependabot[bot] in https://github.com/Budibase/budibase/pull/18967
  • build(deps-dev): bump esbuild from 0.18.20 to 0.28.1 in the all-non-major-security group across 1 directory by @dependabot[bot] in https://github.com/Budibase/budibase/pull/18974
  • [VULN-80] Fix broken access control on internal table search by @jvcalderon in https://github.com/Budibase/budibase/pull/18962

Full Changelog: https://github.com/Budibase/budibase/compare/3.39.15...3.39.16

Security Fixes

  • [VULN-80] Fix broken access control on internal table search

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track budibase

Get notified when new releases ship.

Sign up free

About budibase

AI agents that run your operations. Model agnostic.

All releases →

Related context

Beta — feedback welcome: [email protected]