


Perceptive Security
SOC/SIEM Consultancy

Budibase is an open-source low-code platform. Prior to 3.34.8, the processUrlFile function in packages/server/src/automations/steps/ai/extract.ts uses fetch(fil…
Published:
26 May 2026 at 22:00:00
Alert date:
27 May 2026 at 19:08:13
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
Budibase open-source low-code platform contains a server-side request forgery (SSRF) vulnerability in versions prior to 3.34.8. The vulnerability exists in the processUrlFile function which lacks IP blacklist validation, allowing authenticated users to trigger requests to internal network addresses. The flaw is in the automation steps AI extract functionality and has been fixed in version 3.34.8.
Technical details
Mitigation steps:
Affected products:
Budibase
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-45548
https://github.com/Budibase/budibase/releases/tag/3.38.4
https://github.com/Budibase/budibase/security/advisories/GHSA-rpj4-7x2v-wjrf
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
