Budibase through 3.41.0 contains a server-side request...
High severity
Unreviewed
Published
Oct 1, 2026
to the GitHub Advisory Database
•
Updated Oct 1, 2026
Description
Published by the National Vulnerability Database
Oct 1, 2026
Published to the GitHub Advisory Database
Oct 1, 2026
Last updated
Oct 1, 2026
Budibase through 3.41.0 contains a server-side request forgery vulnerability in AI table generation because the uploadUrl function in packages/server/src/utilities/fileUtils.ts uses raw node-fetch instead of fetchWithBlacklist. Authenticated builder users can send a prompt to POST /api/ai/tables that places an internal URL in an attachment column, causing the server to fetch it and return a presigned object-storage URL containing the response, such as cloud metadata credentials.
References