Loading…
CVE-2026-42239 — Budibase auth session cookies are set with httpOnly:false — any XSS can lead to · VulnScope