Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector
This is a related but independently fixable vulnerability to GHSA-qqf5-x7mj-v43p (PostgreSQL SQL injection), reported in the same original disclosure and split per GitHub CNA guidance (rule 4.2.11) since it affects a separate integration, has a distinct attack precondition, and requires a separate patch.
The MySQL integration enables multipleStatements: true on the connection,
permitting semicolon-separated multi-statement execution. During table
introspection, table names retrieved from INFORMATION_SCHEMA.TABLES are
interpolated into a DESCRIBE query wrapped in backticks, but embedded
backticks in the table name are never escaped — allowing a malicious table
name to break out and inject a second, attacker-controlled statement.
Vulnerable Code:
File: packages/server/src/integrations/mysql.ts, lines 172, 305
this.config = { ...config, multipleStatements: true, ... } // line 172
...
{ sql: `DESCRIBE \`${tableName}\`;` } // line 305 — backtick NOT escaped
Because multipleStatements is enabled, any statement appended after the
backtick break-out executes as a second query in the same round trip.
foo`; DROP TABLE users; --INFORMATION_SCHEMA.TABLES
and interpolates it into the DESCRIBE query.multipleStatements: true)
executes as a second statement.Arbitrary SQL execution triggered during routine schema discovery. Unlike the PostgreSQL and MS SQL Server findings, this does not require the attacker to control the Budibase datasource configuration directly — only the ability to create a maliciously named table in the underlying database beforehand, with an administrator's normal use of the introspection feature serving as the trigger.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도 | 76.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 76.00 |
VPI 공식 vpi-v1 기준