budibase:auth of the file packages/backend-core/src/utils/utils.ts. Performing a manipulation results in cookie without 'httponly' flag.This vulnerability is reported as CVE-2026-42239. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
SOCIAL SHARE CARD GENERATOR