CVE-2026-103757
Deferred Deferred - Pending Action

Server-Side Request Forgery in Budibase AI Table Generation

Vulnerability report for CVE-2026-103757, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulnCheck

Description

Budibase through 3.41.0 contains a server-side request forgery vulnerability in AI table generation because the uploadUrl function in packages/server/src/utilities/fileUtils.ts uses raw node-fetch instead of fetchWithBlacklist. Authenticated builder users can send a prompt to POST /api/ai/tables that places an internal URL in an attachment column, causing the server to fetch it and return a presigned object-storage URL containing the response, such as cloud metadata credentials.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
budibase budibase to 3.41.0 (inc)
budibase budibase to 3.41.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Server-Side Request Forgery (SSRF) vulnerability in Budibase versions before 3.41.0. It exists in the AI table generation feature due to the uploadUrl function using raw node-fetch instead of a blacklisted fetch method. Authenticated builder users can send a prompt to POST /api/ai/tables with an internal URL in an attachment column, causing the server to fetch it and return a presigned object-storage URL containing the response, potentially exposing sensitive data like cloud metadata credentials.

Detection Guidance

To detect this SSRF vulnerability in Budibase, monitor network traffic for unexpected outbound requests from the Budibase server to internal IP ranges (e.g., 169.254.169.254) or private addresses. Check logs for POST requests to /api/ai/tables with URLs in attachment columns. Verify if the uploadUrl function in packages/server/src/utilities/fileUtils.ts uses raw node-fetch instead of fetchWithBlacklist.

Impact Analysis

An attacker with builder role access could exploit this to fetch internal URLs, potentially stealing cloud metadata credentials (e.g., AWS IAM credentials) or accessing internal services like CouchDB, Redis, or MinIO. The vulnerability allows full-read SSRF, meaning the attacker can read responses from internal systems.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection principles and HIPAA's security requirements for protected health information. Exposure of cloud metadata or internal service credentials may result in compliance breaches, data leaks, or unauthorized system access.

Mitigation Strategies

Upgrade Budibase to version 3.41.0 or later to apply the patch. Ensure the uploadUrl function uses fetchWithBlacklist to block private IP ranges. Restrict access to the /api/ai/tables endpoint to authorized builder users only. Monitor for unusual network activity or unauthorized data exfiltration attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103757. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart