Outdated VectorDB Configuration in Budibase Allows Unrestricted Host Parameter Submission
CVE-2026-48148
5.3MEDIUM
What is CVE-2026-48148?
Budibase, an open-source low-code platform, contains a vulnerability in its VectorDB configuration endpoint where the host parameter is accepted without adequate validation checks. This lack of validation permits authenticated users with builder-level access to input arbitrary host values. Consequently, this can lead the server to establish outbound TCP connections to internal network addresses or cloud metadata endpoints, posing a significant security risk. The issue has been addressed in version 3.35.3, underscoring the importance of keeping software up-to-date to mitigate such risks.
Affected Version(s)
budibase < 3.35.3
