Executive brief
Budibase, a low-code platform for building business applications, contains a server-side request forgery (SSRF) vulnerability in its OAuth2 configuration validation. An attacker with builder-level access can supply a malicious OAuth2 token endpoint URL that causes the server to make requests to internal services (such as databases or cloud metadata endpoints) and leak response data. This allows attackers to read other tenants' data on shared Budibase Cloud instances or steal AWS credentials from instance metadata.
Technical details
The vulnerability exists in fetchToken (packages/server/src/sdk/workspace/oauth2/utils.ts) which makes a POST request to a builder-controlled URL using plain node-fetch without consulting blacklist.isBlacklisted(), unlike every other outbound fetch path in the codebase. The /api/oauth2/validate endpoint accepts any URL string via Joi.string().required() with no scheme or host restrictions, and returns validation error messages that leak upstream response bodies. The fetchConfig uses redirect: "follow" (default), enabling attacker chaining through public 302 redirects to internal targets. Successful exploitation requires builder role access (available on Budibase Cloud with free-tier signup). The default blacklist blocks 127.0.0.0/8, 169.254.0.0/16, 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16. The fix is to call blacklist.isBlacklisted() before fetch and set redirect: "manual", matching the pattern in outboundFetch.ts. Patched in version 3.39.0.
Affected products
- Budibase @budibase/server < 3.39.0
Timeline
- 2026-05-27: disclosed
- 2026-06-22: patched: Version 3.39.0 released