Server-Side Request Forgery in Budibase Low-Code Platform
CVE-2026-48128
5.1MEDIUM
What is CVE-2026-48128?
Budibase, an open-source low-code platform, has a vulnerability in its executeQuery automation step. Before version 3.39.0, this step accepts a queryId from automation inputs and passes it directly to the query execution controller without adequate validation. This flaw can be exploited through a REST data source aimed at internal infrastructure, leading to a server-side request forgery. As a result, automated requests may be executed that target malicious destinations, potentially exposing sensitive internal data through the automation output. The vulnerability has been addressed in version 3.39.0.
Affected Version(s)
budibase < 3.39.0
