CVE-2026-45548

Budibase is an open-source low-code platform. Prior to 3.34.8, the processUrlFile function in packages/server/src/automations/steps/ai/extract.ts uses fetch(fileUrl) directly without the IP blacklist validation that is consistently applied to all other automation steps. This allows an authenticated user to trigger server-side requests to internal network addresses. This vulnerability is fixed in 3.34.8.
Configurations

No configuration.

History

27 May 2026, 20:16

Type Values Removed Values Added
References () https://github.com/Budibase/budibase/security/advisories/GHSA-rpj4-7x2v-wjrf - () https://github.com/Budibase/budibase/security/advisories/GHSA-rpj4-7x2v-wjrf -

27 May 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-27 18:16

Updated : 2026-06-17 10:52


NVD link : CVE-2026-45548

Mitre link : CVE-2026-45548

CVE.ORG link : CVE-2026-45548


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)