CVE-2026-103757
Budibase before 3.41.0 SSRF via uploadUrl in AI Table Generation
CVSS Score
7.7
EPSS Score
0.0%
EPSS Percentile
0th
Budibase through 3.41.0 contains a server-side request forgery vulnerability in AI table generation because the uploadUrl function in packages/server/src/utilities/fileUtils.ts uses raw node-fetch instead of fetchWithBlacklist. Authenticated builder users can send a prompt to POST /api/ai/tables that places an internal URL in an attachment column, causing the server to fetch it and return a presigned object-storage URL containing the response, such as cloud metadata credentials.
| CWE | CWE-918 |
| Vendor | budibase |
| Product | budibase |
| Published | Oct 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for budibase budibase
Be the first to know when new high vulnerabilities affecting budibase budibase are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
Budibase / budibase
0 < 3.41.0
References
Credits
๐ sfwani