GHSA-q6x4-v3qx-85qw
## Summary A critical SQL injection vulnerability was discovered in Budibase's MySQL integration that allows remote attackers to execute arbitrary SQL commands. ## Details ### Vulnerability Type SQL Injection ### Description The MySQL integration component in Budibase is configured with `multipleStatements: true`, enabling execution of multiple SQL statements in a single query. Attackers can inject malicious SQL commands through user input fields, leading to complete database compromise. ### Location ```typescript // File: packages/server/src/integrations/mysql.ts // Line: 173 this.config = { ...config, typeCast: defaultTypeCasting, multipleStatements: true, // VULNERABLE timezone: "Z", } ``` ## Proof of Concept ### Exploit ```javascript const mysql = require('mysql2'); // Budibase vulnerable configuration const connection = mysql.createConnection({ host: 'localhost', user: 'root', password: 'password', multipleStatements: true, // Vulnerable setting timezone: "Z" }); // Attack: Data destruction connection.query( `SELECT * FROM users WHERE id = 1; DROP TABLE sensitive_data; --`, (err, results) => { if (!err) console.log("Table dropped successfully"); } ); ``` ## Impact - **Data Destruction**: Execute DROP TABLE, DELETE commands - **Data Theft**: Exfiltrate data via SELECT INTO OUTFILE - **Privilege Escalation**: Grant database admin privileges - **Denial of Service**: Disrupt service operations - **Complete Database Compromise**: Full control over database ## Remediation ### Patch ```diff --- a/packages/server/src/integrations/mysql.ts +++ b/packages/server/src/integrations/mysql.ts @@ -170,7 +170,7 @@ class MySQLIntegration extends Sql implements DatasourcePlus { this.config = { ...config, typeCast: defaultTypeCasting, - multipleStatements: true, + multipleStatements: false, timezone: "Z", } } ``` ### Workarounds 1. Temporarily disable MySQL integration 2. Implement web application
Properties
- ghsa_id
- GHSA-q6x4-v3qx-85qw
- severity
- critical
- summary
- Budibase: SQL Injection via `multipleStatements: true`
- cvss_score
- 9.6
- cve_id
- GHSA-q6x4-v3qx-85qw
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- is_ghsa_only
- true
- ghsa_published
- 2026-07-24T21:15:02Z
- source_url
- https://github.com/advisories/GHSA-q6x4-v3qx-85qw
- ghsa_updated
- 2026-07-24T21:15:02Z
Related Entities (4)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
Explore deeper with Ninja Signal's threat intelligence graph