What happened
A server-side request forgery in Budibase's AI table-generation feature: the uploadUrl helper fetches user-supplied attachment URLs with unfiltered node-fetch, allowing authenticated builder users to turn the AI table prompt into a fetch of internal addresses and read the response back through the presigned-URL leak.
Why it matters
Budibase's AI features are the trigger surface, but the real blast radius is the Budibase host: AI-generated tables are a privileged, user-controllable path into the internal network and cloud IAM metadata. For AI deployments it is a concrete example of an AI feature endpoint becoming an SSRF primitive.
Attack vector
An authenticated builder user sends a prompt to POST /api/ai/tables that places an internal URL in an attachment column; the uploadUrl function in packages/server/src/utilities/fileUtils.ts uses raw node-fetch instead of the blacklisted fetchWithBlacklist variant, so the server fetches the internal URL (e.g. cloud metadata 169.254.x.x) and returns the response inside a presigned object-storage URL to the caller (CVSS 7.7, SSRF with credential disclosure).
Affected systems
Budibase through 3.41.0
Mitigation
Patch per GitHub advisory GHSA-3c52-v5v2-3r56 (fix released for 3.41.x) — route AI table uploads through the URL-blacklisting fetch path; restrict builder-user trust