Junglewise Threat Intelligence

CVE-2026-33226: Budibase unrestricted SSRF in REST datasource query preview

CVE-2026-33226 · Severity: low · CVSS 3.1 · Published 2026-03-18

Technologies: budibase (npm), Budibase. Vendors: npm, Budibase.

Executive brief

Budibase is a low-code application platform that allows administrators to build apps and automations. The REST datasource query preview feature allows authenticated admins to execute arbitrary server-side HTTP requests without validation, enabling them to access internal cloud metadata services, databases, and Kubernetes APIs that should be isolated from the internet. On cloud platforms like GCP, this can result in theft of cloud access tokens granting full administrative control over cloud resources.

Technical details

The vulnerability is a Server-Side Request Forgery (SSRF) in the POST /api/queries/preview endpoint (packages/server/src/api/controllers/query.ts, preview() handler). The endpoint accepts a user-supplied URL in the fields.path parameter and passes it directly to the REST HTTP client without any validation of IP ranges, hostnames, or domains. No blocklist exists for loopback (127.0.0.1, ::1), RFC 1918 private ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16), link-local/cloud metadata (169.254.0.0/16), or Kubernetes internal DNS (.svc.cluster.local). An authenticated admin or builder user can exploit this by supplying a datasourceId (trivially obtained via GET /api/datasources or created on-demand) and a malicious path parameter to reach internal services including cloud metadata endpoints (AWS/GCP/Azure), internal databases, Kubernetes APIs, and other internal pods. Confirmed impact includes GCP OAuth2 token theft from 169.254.169.254, CouchDB access, MinIO and Redis enumeration, and K8s API access via mounted service account tokens. Patched versions have not been released as of the advisory date.

Affected products

  • Budibase budibase <=3.30.6

Timeline

  • 2026-03-18: disclosed: Advisory GHSA-4647-wpjq-hh7f published
  • 2026-03-20: advisory: CVE-2026-33226 published on NVD

References

Related threats