PT-2026-83098 · Budibase · @Budibase/Server
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Budibase Server versions prior to 3.41.3
Description
An issue exists in the query import endpoint where the system fails to validate user-supplied URLs before fetching content. This allows attackers to perform a Server-Side Request Forgery (SSRF)—a technique where a server is tricked into making requests to an unintended location—to retrieve responses from internal services, including cloud metadata endpoints and other restricted network resources.
Recommendations
Update Budibase Server to version 3.41.3 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Budibase/Server