Outdated VectorDB Configuration in Budibase Allows Unrestricted Host Parameter Submission
CVE-2026-48148

5.3MEDIUM

Key Information:

Vendor

Budibase

Status
Vendor
CVE Published:
27 May 2026

What is CVE-2026-48148?

Budibase, an open-source low-code platform, contains a vulnerability in its VectorDB configuration endpoint where the host parameter is accepted without adequate validation checks. This lack of validation permits authenticated users with builder-level access to input arbitrary host values. Consequently, this can lead the server to establish outbound TCP connections to internal network addresses or cloud metadata endpoints, posing a significant security risk. The issue has been addressed in version 3.35.3, underscoring the importance of keeping software up-to-date to mitigate such risks.

Affected Version(s)

budibase < 3.35.3

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.