CVE-2026-35219High▾ TwilightBudibase is an open-source low-code platform. Prior to 3.41.3, automation steps in packages/server/src/automations/steps/outgoingWebhook.ts, packages/server/src/automations/steps/zapier.ts, packages/server/src/automations/steps/n8n.ts, p…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.5%
Last analysed / modified upstream
Budibase is an open-source low-code platform. Prior to 3.41.3, automation steps in packages/server/src/automations/steps/outgoingWebhook.ts, packages/server/src/automations/steps/zapier.ts, packages/server/src/automations/steps/n8n.ts, packages/server/src/automations/steps/slack.ts, and packages/server/src/automations/steps/discord.ts use node-fetch on user-provided URLs without the BLACKLIST_IPS enforcement used by the REST integration, allowing an authenticated user to make server-side requests to cloud metadata and internal services. This issue is fixed in version 3.41.3.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
@budibase/server < 3.41.3Patched in:
@budibase/server 3.41.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-54356High· 7.1Budibase is an open-source low-code platform
GHSA-v42f-v8xc-j435High· 8.5Budibase: SSRF via DNS rebinding in the REST datasource integration
GHSA-hfhx-w8p8-4hc7MediumBudibase: SSRF via bare fetch() in uploadUrl during AI table generation
GHSA-xg5g-26x8-cvf4High· 8.5Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution
CVE-2026-48146High· 7.7Budibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist Protection
CVE-2026-48148MediumBudibase: Unvalidated VectorDB Host Parameter Enables SSRF