


Perceptive Security
SOC/SIEM Consultancy

Budibase is an open-source low-code platform. Prior to 3.34.8, the processUrlFile function in packages/server/src/automations/steps/ai/extract.ts uses fetch(fil…
Published:
26 mei 2026 om 22:00:00
Alert date:
27 mei 2026 om 20:13:41
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
Budibase, an open-source low-code platform, contains a Server-Side Request Forgery (SSRF) vulnerability in versions prior to 3.34.8. The processUrlFile function in the AI extract automation step bypasses IP blacklist validation, allowing authenticated users to make requests to internal network addresses. This could enable attackers to probe internal systems and potentially access sensitive resources. The vulnerability has been patched in version 3.34.8.
Technical details
Mitigation steps:
Affected products:
Budibase
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-45548
https://github.com/Budibase/budibase/releases/tag/3.38.4
https://github.com/Budibase/budibase/security/advisories/GHSA-rpj4-7x2v-wjrf
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
