{"id":"CVE-2026-103757","title":"Budibase through 3.41.0 contains a server-side request forgery vulnerability in AI table generation because the uploadUrl function in packages/server/src/utilities/fileUtils.ts uses raw node-fetch instead of fetchWithBlacklist","summary":"Budibase through 3.41.0 contains a server-side request forgery vulnerability in AI table generation because the uploadUrl function in packages/server/src/utilities/fileUtils.ts uses raw node-fetch instead of fetchWithBlacklist. Authentic…","severity":"high","cvss":7.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","cwe":["CWE-918"],"vendor":"Budibase","product":"budibase","affected":["budibase < 3.41.0"],"published":"2026-10-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T11:17:26.310","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-103757","references":[{"url":"https://github.com/Budibase/budibase/security/advisories/GHSA-3c52-v5v2-3r56","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/budibase-before-3.41.0-ssrf-via-uploadurl-in-ai-table-generation","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org","exploit-available"],"ingestedAt":"2026-10-01T11:42:53.816Z","exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-01T13:21:24.130408Z"},"slug":"CVE-2026-103757","body":"## Overview\n\nBudibase through 3.41.0 contains a server-side request forgery vulnerability in AI table generation because the uploadUrl function in packages/server/src/utilities/fileUtils.ts uses raw node-fetch instead of fetchWithBlacklist. Authenticated builder users can send a prompt to POST /api/ai/tables that places an internal URL in an attachment column, causing the server to fetch it and return a presigned object-storage URL containing the response, such as cloud metadata credentials.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":42.4,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":214281,"id":"CVE-2026-103757","ts":1790862375491,"field":"exploit_available","old":"false","new":"true"}]}