PT-2026-44056 · Budibase · Budibase

Fg0X0

·

Published

2026-05-27

·

Updated

2026-06-12

·

CVE-2026-48128

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Budibase versions prior to 3.39.0
Description The executeQuery automation step accepts a queryId from automation step inputs and passes it to the query execution controller without additional validation. When a REST datasource is configured to target internal infrastructure, this allows for server-side request forgery (SSRF), a flaw where the server is coerced into making outbound HTTP requests to destinations influenced by an attacker. The automation output then returns the response, which can expose internal service data.
Recommendations Update to version 3.39.0.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48128
GHSA-6964-PP88-6WP9

Affected Products

Budibase