Budibase Server before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB query execution endpoint where user-supplied parameters are interpolated into JSON query templates without proper sanitization of JSON metacharacters. Attackers with query write permission can inject JSON structural characters to alter MongoDB queries, bypassing filters to read, modify, or delete arbitrary documents.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
Budibase Server versions before 3.40.0 contain a critical NoSQL injection vulnerability in the MongoDB query execution endpoint. The vulnerability stems from unsanitized interpolation of user-supplied parameters directly into JSON query templates, allowing attackers with query write permissions to inject JSON metacharacters and fundamentally alter MongoDB queries. This affects organizations using Budibase for data management and application development, particularly those exposing query functionality to users or integrating Budibase in multi-tenant environments where privilege boundaries exist. The CVSS 8.3 rating reflects the high severity due to potential unauthorized data access, modification, and deletion across arbitrary documents in connected MongoDB instances.
While this CVE lacks direct MITRE ATT&CK technique mappings, Casky's security skills leverage Claude AI's extended reasoning to detect the underlying attack patterns associated with NoSQL injection: T1190 (Exploit Public-Facing Application) during the initial injection phase, T1021 (Remote Services) if attackers gain elevated MongoDB access, and T1040 (Network Sniffing) if authentication credentials are exposed through query manipulation. Practitioners using Casky would observe detection findings focused on anomalous MongoDB query structures, unexpected JSON character sequences in application logs, unusual data access patterns deviating from baseline query templates, and authentication anomalies suggesting privilege escalation attempts. The platform's mapping to CWE-943 (Improper Neutralization of Structural Elements in Data Query Logic) helps practitioners understand the root cause and correlate similar injection vulnerabilities across their technology stack.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-73618. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation