CVE-2026-48128

Budibase is an open-source low-code platform. Prior to 3.39.0, the executeQuery automation step in Budibase accepts a queryId from automation step inputs and passes it directly to the query execution controller without additional validation. When combined with a REST datasource configured to target internal infrastructure, this creates a server-side request forgery path where automation execution causes the Budibase server to make outbound HTTP requests to attacker-influenced destinations. The automation output then returns the response, potentially exposing internal service data. This vulnerability is fixed in 3.39.0.
CVSS

No CVSS.

Configurations

No configuration.

History

27 May 2026, 20:16

Type Values Removed Values Added
References () https://github.com/Budibase/budibase/security/advisories/GHSA-6964-pp88-6wp9 - () https://github.com/Budibase/budibase/security/advisories/GHSA-6964-pp88-6wp9 -

27 May 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-27 18:16

Updated : 2026-05-27 20:16


NVD link : CVE-2026-48128

Mitre link : CVE-2026-48128

CVE.ORG link : CVE-2026-48128


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)