CVE-2026-30240 | budibase up to 3.31.5 ZIP /api/pwa/process-zip join path traversal (GHSA-pqcr-jmfv-c9cp)
A vulnerability, which was classified as critical, was found in budibase up to 3.31.5. Affected is the function join of the file /api/pwa/process-zip of the component ZIP Handler. Executing a manipulation can lead to path traversal.
This vulnerability is handled as CVE-2026-30240. The attack can be executed remotely. There is not any exploit available.