PT-2026-44059 · Budibase · Budibase

Fg0X0

·

Published

2026-05-27

·

Updated

2026-06-12

·

CVE-2026-48148

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Budibase versions prior to 3.35.3
Description The VectorDB configuration endpoint accepts a host parameter that lacks validation against internal IP ranges, reserved hostnames, or URL schemes. This allows an authenticated user with builder-level access to provide arbitrary host values, such as localhost or 169.254.169.254, forcing the server to initiate outbound TCP connections to internal network addresses or cloud metadata endpoints.
Recommendations Update to version 3.35.3.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48148
GHSA-CV96-5348-P5P8

Affected Products

Budibase