Server-Side Request Forgery in Budibase AI Table Generation
CVE-2026-103757
8.3HIGH
What is CVE-2026-103757?
Budibase, in versions prior to 3.41.0, contains a server-side request forgery (SSRF) vulnerability in its AI table generation feature. This arises from the uploadUrl function within the fileUtils utility, which employs raw node-fetch instead of a secured fetchWithBlacklist. By exploiting this vulnerability, authenticated builder users can send requests to POST /api/ai/tables with crafted prompts that embed internal URLs in attachment columns. This leads to the server fetching these URLs, ultimately exposing sensitive data such as presigned object-storage URLs and potential cloud metadata credentials.
Affected Version(s)
budibase 0 < 3.41.0
budibase 3.41.0
