


Perceptive Security
SOC/SIEM Consultancy

Budibase is an open-source low-code platform. Prior to 3.39.0, fetchToken in the OAuth2 SDK makes a POST to a builder-supplied URL with plain node-fetch, skippi…
Published:
26 mei 2026 om 22:00:00
Alert date:
27 mei 2026 om 20:13:41
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
Budibase, an open-source low-code platform, contains a server-side request forgery vulnerability in versions prior to 3.39.0. The fetchToken function in the OAuth2 SDK makes POST requests to builder-supplied URLs using plain node-fetch, bypassing the blacklist.isBlacklisted security check that protects other outbound fetch operations. The Joi schema validation for OAuth2 URLs lacks proper scheme and host restrictions, allowing potential abuse. This security flaw has been addressed in version 3.39.0 with proper validation and blacklist checking.
Technical details
Mitigation steps:
Affected products:
Budibase
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-48153
https://github.com/Budibase/budibase/security/advisories/GHSA-4q6h-8p4v-67vq
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
