PT-2026-44056 · Budibase · Budibase
Fg0X0
·
Published
2026-05-27
·
Updated
2026-06-12
·
CVE-2026-48128
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Budibase versions prior to 3.39.0
Description
The
executeQuery automation step accepts a queryId from automation step inputs and passes it to the query execution controller without additional validation. When a REST datasource is configured to target internal infrastructure, this allows for server-side request forgery (SSRF), a flaw where the server is coerced into making outbound HTTP requests to destinations influenced by an attacker. The automation output then returns the response, which can expose internal service data.Recommendations
Update to version 3.39.0.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Budibase