File Attachment Vulnerability in Budibase Low-Code Platform
CVE-2026-73307
4.9MEDIUM
What is CVE-2026-73307?
Budibase, an open-source low-code platform, was found to have a vulnerability where string attachment values could be fetched without adequate validation. This issue arose in versions before 3.39.4, specifically within the uploadUrl functionality. A builder utilizing the AI table-generation feature could inadvertently expose internal services or cloud metadata endpoints. The resultant responses may be saved as attachments, bypassing crucial fetchWithBlacklist validations, potentially leading to unauthorized data exposure. This vulnerability has been addressed in version 3.39.4.
Affected Version(s)
budibase < 3.39.4
