CVE-2026-35219 is a high-severity vulnerability affecting @budibase/server versions < 3.41.3 with a CVSS score of 7.1, classified as a Server-Side Request Forgery (SSRF) flaw. The issue affects Budibase automation steps that make server-side HTTP requests to user-provided URLs using the node-fetch library directly, completely bypassing the IP blacklist protection in the REST API integration. This allows any user to create automations with steps pointing to internal IPs, granting access to cloud metadata, databases, admin panels, Kubernetes API on private IPs, and potentially other internal services. The vulnerability also affects the REST API itself, which defaults to an empty blacklist when the BLACKLIST_IPS environment variable is not configured. To exploit this flaw, an attacker can craft a malicious URL that points to an internal IP address, allowing them to access sensitive resources within the network. This vulnerability has significant business impact, as it enables unauthorized access to critical infrastructure and data.
We recommend you to update Budibase to version 3.41.3.[/subscribe_to_unlock_form]
CVE-2026-35219 is a high-severity vulnerability affecting @budibase/server versions < 3.41.3 with a CVSS score of 7.1, classified as a Server-Side Request Forgery (SSRF) flaw. The issue affects Budibase automation steps that make server-side HTTP requests to user-provided URLs using the node-fetch library directly, completely bypassing the IP blacklist protection in the REST API integration. This allows any user to create automations with steps pointing to internal IPs, granting access to cloud metadata, databases, admin panels, Kubernetes API on private IPs, and potentially other internal services. The vulnerability also affects the REST API itself, which defaults to an empty blacklist when the BLACKLIST_IPS environment variable is not configured. To exploit this flaw, an attacker can craft a malicious URL that points to an internal IP address, allowing them to access sensitive resources within the network. This vulnerability has significant business impact, as it enables unauthorized access to critical infrastructure and data.
We recommend you to update Budibase to version 3.41.3.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]