CVE-2026-48147 | budibase up to 3.35.3 Worker API Endpoint buildMatcherRegex incorrect regex (GHSA-wxq7-x3qp-vcr8)
A vulnerability described as problematic has been identified in budibase up to 3.35.3. This vulnerability affects the function buildMatcherRegex of the component Worker API Endpoint. Executing a manipulation can lead to incorrect regular expression.
This vulnerability is registered as CVE-2026-48147. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.