Vulnerability  ·  2026-10-02

Budibase AI table generation SSRF reaches internal services and cloud metadata via raw node-fetch

VulnerabilityHigh impactGlobalCVE-2026-103757
A server-side request forgery in Budibase's AI table-generation feature: the uploadUrl helper fetches user-supplied attachment URLs with unfiltered node-fetch, allowing authenticated builder users to turn the AI table prompt into a fetch of internal addresses and read the response back through the presigned-URL leak.
Budibase's AI features are the trigger surface, but the real blast radius is the Budibase host: AI-generated tables are a privileged, user-controllable path into the internal network and cloud IAM metadata. For AI deployments it is a concrete example of an AI feature endpoint becoming an SSRF primitive.
An authenticated builder user sends a prompt to POST /api/ai/tables that places an internal URL in an attachment column; the uploadUrl function in packages/server/src/utilities/fileUtils.ts uses raw node-fetch instead of the blacklisted fetchWithBlacklist variant, so the server fetches the internal URL (e.g. cloud metadata 169.254.x.x) and returns the response inside a presigned object-storage URL to the caller (CVSS 7.7, SSRF with credential disclosure).
Budibase through 3.41.0
Patch per GitHub advisory GHSA-3c52-v5v2-3r56 (fix released for 3.41.x) — route AI table uploads through the URL-blacklisting fetch path; restrict builder-user trust
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →