Skip to content

budibase

v3.39.25 Security

This release includes 3 security fixes for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 3 known CVEs

Topics

ai-app-builder ai-applications crud-app crud-application data-application data-apps
+12 more
internal-tools it-workflows low-code low-code-no-code low-code-platform no-code no-code-platform rest-api-framework sql-gui workflow-apps workflow-automation workflow-engine

Affected surfaces

auth rbac

Summary

AI summary

Require builder access for group listing, align login lockout for unknown users, and strip SSO tokens from user metadata.

Full changelog

What's Changed

  • Revert "feat: full screen logs UI" by @Dakuan in https://github.com/Budibase/budibase/pull/19111
  • [Codex] [108] Require builder access for group listing by @Dakuan in https://github.com/Budibase/budibase/pull/19109
  • [Codex] [106] Align login lockout for unknown users by @Dakuan in https://github.com/Budibase/budibase/pull/19108
  • [codex] Quote Oracle row lookup identifiers by @Dakuan in https://github.com/Budibase/budibase/pull/19100
  • [Codex] [105] Sanitize automation test OAuth outputs by @Dakuan in https://github.com/Budibase/budibase/pull/19107
  • [Codex] [107] Strip SSO tokens from user metadata by @Dakuan in https://github.com/Budibase/budibase/pull/19110
  • Improve automation connector connection flow by @melohagan in https://github.com/Budibase/budibase/pull/19051
  • Restore QueryViewer fields by @melohagan in https://github.com/Budibase/budibase/pull/19125

Full Changelog: https://github.com/Budibase/budibase/compare/3.39.24...3.39.25

Breaking Changes

  • [Codex] Require builder access for group listing

Security Fixes

  • [Codex] Align login lockout for unknown users — prevents abuse via repeated failed logins
  • [Codex] Strip SSO tokens from user metadata — removes sensitive token leakage
  • [Codex] Sanitize automation test OAuth outputs — mitigates potential information exposure

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track budibase

Get notified when new releases ship.

Sign up free

About budibase

AI agents that run your operations. Model agnostic.

All releases →

Related context

Beta — feedback welcome: [email protected]