Server-Side Request Forgery in Budibase AI Table Generation
CVE-2026-103757

8.3HIGH

Key Information:

Vendor

Budibase

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-103757?

Budibase, in versions prior to 3.41.0, contains a server-side request forgery (SSRF) vulnerability in its AI table generation feature. This arises from the uploadUrl function within the fileUtils utility, which employs raw node-fetch instead of a secured fetchWithBlacklist. By exploiting this vulnerability, authenticated builder users can send requests to POST /api/ai/tables with crafted prompts that embed internal URLs in attachment columns. This leads to the server fetching these URLs, ultimately exposing sensitive data such as presigned object-storage URLs and potential cloud metadata credentials.

Affected Version(s)

budibase 0 < 3.41.0

budibase 3.41.0

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

sfwani
.