Junglewise Threat Intelligence

CVE-2026-45061: Budibase SSRF via URL validation bypass in Plugin upload

CVE-2026-45061 · Severity: high · CVSS 7.7 · Published 2026-05-27

Technologies: budibase (npm), Budibase. Vendors: npm, Budibase.

Executive brief

Budibase, a low-code platform for building business applications, is vulnerable to a security flaw in how it handles plugin installations from web addresses. An attacker with basic developer permissions can trick the server into making requests to internal systems that should be private, such as cloud metadata services or internal databases. This could lead to the theft of sensitive credentials or internal data, potentially compromising the underlying infrastructure where Budibase is hosted.

Technical details

The Plugin URL upload endpoint (`POST /api/plugin`) in Budibase (Self-Hosted) versions <= 3.34.11 performs inadequate URL validation by only checking if the string contains the substring '.tar.gz'. This allows an attacker with 'Global Builder' privileges to bypass the check using crafted URLs like 'http://169.254.169.254/.tar.gz'. While Budibase employs an IP blacklist, this protection can be bypassed if the blacklist is misconfigured (empty) or if the server follows HTTP redirects from an external allowed domain to an internal blocked IP. Successful exploitation allows an attacker to perform GET requests against internal services, cloud metadata endpoints (IMDS), or local databases. The issue is fixed in version 3.35.10.

Affected products

  • Budibase Budibase <= 3.34.11

Timeline

  • 2026-03-30: other: Vulnerability identified in version 3.34.11
  • 2026-05-07: advisory: GitHub Advisory published
  • 2026-05-11: disclosed: CVE-2026-45061 disclosed
  • 2026-06-08: other: Advisory updated

References

Related threats